Startup security in macOS Flashcards

https://support.apple.com/en-ph/guide/deployment/dep5810e849c/web

1
Q

What are the three security policies for a Mac with Apple silicon?

A

Full Security: The system behaves like iOS and iPadOS, and allows only booting software that was known to be the latest that was available at install time.

Reduced Security: This policy level allows the system to run older versions of macOS.

Permissive Security: This policy level supports users that are building, signing, and booting their own custom XNU kernels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

System Integrity Protection (SIP) must be disabled before enabling Permissive Security Mode

A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Multiple installed macOS instances with different versions and security policies can be supported by the Mac with Apple Silicon

A. True
B. False

A

A. True

For this reason, an operating system picker has been added to Startup Security Utility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

macOS utilizes kernel permissions to limit writability of critical system files with a feature called ____

A

System Integrity Protection (SIP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Hardware-based ____ , available on a Mac with Apple silicon, protects modification of the kernel in memory

A

Kernel Integrity Protection (KIP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

____ are policies that set security restrictions, created by the developer, that can’t be overridden

A

Mandatory access controls

Mandatory access controls aren’t visible to users, but they’re the underlying technology that helps enable several important features, including sandboxing, parental controls, managed preferences, extensions, and System Integrity Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why does System Integrity Protection restrict components to read-only in specific critical file system locations?

A

To help prevent malicious code from modifying them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which security policy is the default for macOS?

A

Full Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the 64-bit identifier that’s unique to the processor in each iPhone or iPad?

A

Exclusive Chip Identification (ECID)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where can you access Startup Security Utility?

A

recoveryOS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Permissive Security can be accessed only from command-line tools for users who accept the risk of making their Mac much less secure

A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which security policy is similar to “Medium Security” behavior on an intel-based Mac with a T2 chip?

A

Reduced Security policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Apple provides/support custom XNU kernels

A. True
B. False

A

B. False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which command disables SIP when using Terminal?

A

csrutil

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The configuration of starting from external media is always explicitly enabled on a per operating system basis, and already requires user authorization, so no additional secure configuration is necessary.

A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How do you explicitly enable Kexts (Kernel extensions) on a Mac with Apple silicon?

A

Hold power button at startup to enter One True Recovery (1TR) mode, then downgrade to Reduced Security, then check the box to enable kernel extensions

(in recoveryOS, Utilities > Startup Security Utility > Reduced Security)

17
Q

What MDM command sets a recoveryOS password for a Mac with Apple silicon

A

SetRecoveryLock

18
Q

Unenrolling a Mac computer from MDM that has a recoveryOS password set also removes the password

A. True
B. False

A

A. True

19
Q

Which MDM command verifies the correct recoveryOS password?

A

VerifyRecoveryLock

20
Q

Setting a recoveryOS password doesn’t prevent the restoration of a Mac computer with Apple silicon through DFU Mode using Apple Configurator, which also cryptographically renders the previous data on the Mac inaccessible

A. True
B. False

A

A. True

21
Q

For Mac computers without Apple Silicon, a firmware password can be set, updated, or removed using the ____ command-line tool

A

firmwarepasswd

or also with Firmware Password Utility, or MDM