Startup security in macOS Flashcards
https://support.apple.com/en-ph/guide/deployment/dep5810e849c/web
What are the three security policies for a Mac with Apple silicon?
Full Security: The system behaves like iOS and iPadOS, and allows only booting software that was known to be the latest that was available at install time.
Reduced Security: This policy level allows the system to run older versions of macOS.
Permissive Security: This policy level supports users that are building, signing, and booting their own custom XNU kernels
System Integrity Protection (SIP) must be disabled before enabling Permissive Security Mode
A. True
B. False
A. True
Multiple installed macOS instances with different versions and security policies can be supported by the Mac with Apple Silicon
A. True
B. False
A. True
For this reason, an operating system picker has been added to Startup Security Utility.
macOS utilizes kernel permissions to limit writability of critical system files with a feature called ____
System Integrity Protection (SIP)
Hardware-based ____ , available on a Mac with Apple silicon, protects modification of the kernel in memory
Kernel Integrity Protection (KIP)
____ are policies that set security restrictions, created by the developer, that can’t be overridden
Mandatory access controls
Mandatory access controls aren’t visible to users, but they’re the underlying technology that helps enable several important features, including sandboxing, parental controls, managed preferences, extensions, and System Integrity Protection
Why does System Integrity Protection restrict components to read-only in specific critical file system locations?
To help prevent malicious code from modifying them
Which security policy is the default for macOS?
Full Security
What is the 64-bit identifier that’s unique to the processor in each iPhone or iPad?
Exclusive Chip Identification (ECID)
Where can you access Startup Security Utility?
recoveryOS
Permissive Security can be accessed only from command-line tools for users who accept the risk of making their Mac much less secure
A. True
B. False
A. True
Which security policy is similar to “Medium Security” behavior on an intel-based Mac with a T2 chip?
Reduced Security policy
Apple provides/support custom XNU kernels
A. True
B. False
B. False
Which command disables SIP when using Terminal?
csrutil
The configuration of starting from external media is always explicitly enabled on a per operating system basis, and already requires user authorization, so no additional secure configuration is necessary.
A. True
B. False
A. True