Section 3 Review - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Simulation

Access this simulation to complete practice tasks.

Estimated simulation completion time: 10 minutes

Click to view simulation
Note:

Problems viewing this simulation in Safari? Open Preferences > Privacy and disable Prevent cross-site tracking.

Practice

Complete the following additional practice tasks in the macOS Security portal.

  1. Navigate through the following areas of the macOS Security portal: (Lesson 7)

    1. View all CIS Level 2 rules in the compliance baseline.

      1. Navigate to Compliance in the sidebar.

      2. Click the Baseline tab.

      3. Select the CIS Level 2 filter.

    2. Verify the compliance baseline reporting interval in the default plan.

      1. Navigate to Plans in the sidebar.

      2. Select the Default plan.

      3. Click Edit at the top.

      4. Locate the Compliance Baseline Reporting field and note the minutes value set in that field. How often do computers assigned to the default plan report their compliance status?

    3. Verify the number of enrolled computers on the latest version of threat prevention.

      1. Navigate to Threat Prevention in the sidebar.

      2. Under Latest Version, select the computer icon to view enrolled computers.

      3. Note the number of computers currently on the latest version.

  2. Create a custom plan in the macOS Security portal. (Lesson 8)

    1. Navigate to Plans in the sidebar.

    2. Click Create Plan.

    3. Provide a name and description for the new plan.

    4. Under Advanced Threat Controls, select Block and Report.

    5. Under Analytic Sets, choose Default Analytic Set.

    6. Choose "Warning" from the Log Level menu.

    7. Under Endpoint Information Collection, deselect the checkbox for Memory Size.

    8. Under Compliance Baseline Reporting, change the reporting interval to 720 minutes.

    9. Click Save to save the new plan.

  3. Create a custom prevention list for the Discord application. (Lesson 9)

    1. In the macOS Security portal, navigate to Threat Prevention in the sidebar.

    2. Click Custom Prevention Lists.

    3. Click Create Prevent List.

    4. Type Discord in the Name field.

      1. Optional: Provide an appropriate description in the Description field.

    5. Under Prevent Type, select Signing Information.

    6. Select Signing ID.

    7. In the List Data field, type com.hnc.Discord.

    8. Click Save at the top.

  4. Create a telemetry configuration in the macOS Security portal. (Lesson 10)

    1. Navigate to Telemetry in the sidebar.

    2. Click Create Telemetry.

    3. Provide a name and description in their respective fields at the top.

    4. Under Logging, select the checkboxes for Applications and Processes, Persistence, Apple Security, and System.

    5. Under Data collection, select the checkbox for Performance metrics.

    6. Under Simple log file collection, click Add log file and enter /var/log/system.log.

    7. Repeat the previous step twice to also collect the following log files:

      1. /var/log/install.log

      2. /var/log/jamf.log

    8. Click Save at the top to save the telemetry configuration.

Objectives recap

  • Understand the different features of the macOS Security portal and become familiar with navigating the application.

  • Configure the compliance baseline and analytic set that make up the default plan in the macOS Security portal. Deploy the plan to computers.

  • Explore threat prevention and alerts in the macOS Security portal. Safely generate an alert on a test computer and learn how Jamf Protect automatically mitigates threats on enrolled Mac computers.

  • Explore the different data collection and management options in the macOS Security portal.