Be able to run and interpret csrutil status, spctl --assess, kextstat, and systemextensionsctl output, then map results to the right control. The critical skill is distinguishing which macOS security layer is actually responsible for a given block or finding.
Start practicing
macOS Security — choose a session length
Free · No account required
Domain overview
This domain covers macOS platform hardening and threat detection as tested on the GSEC exam: Gatekeeper, notarization, System Integrity Protection, kernel extension controls, FileVault, and the command-line tools used to inspect them. Questions present real command output or a security requirement and ask you to interpret the posture or select the correct control.
Exam objectives
Interpreting Gatekeeper and notarization behavior when a downloaded app is blocked from launching
System Integrity Protection (SIP) and its role in preventing unauthorized kernel and system modifications
Using kextstat, kmutil, and systemextensionsctl to enumerate kernel extensions and system extensions
Reading spctl, csrutil, and codesign output to assess code-signing and security configuration state
Confusing Gatekeeper (app launch policy) with notarization (Apple malware scan) and XProtect (signature-based detection) when identifying the blocking control
Assuming SIP can be disabled at will; it requires booting to Recovery and running csrutil disable, and status must be verified with csrutil status
Treating all kernel extensions as malicious; Apple-signed and user-approved kexts are legitimate, so check signing and approval state before flagging
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?
2Which TWO of the following actions are primarily restricted by macOS System Integrity Protection (SIP)?
3Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretation regarding the security posture of this endpoint?
4A user reports they cannot open a downloaded application because macOS states the developer cannot be verified. Which security feature is preventing the execution of this application?
5What is the primary purpose of the 'Notarization' process for macOS applications?
6A user attempts to launch a newly installed application on a macOS Monterey system, but the application fails to open with a message that it cannot be verified. The user is certain the application was downloaded from the developer's official website. Which macOS feature is responsible for this behavior?
7A security administrator is configuring a macOS fleet to enforce that only apps signed with an Apple-issued Developer ID certificate and notarized by Apple can run. The administrator wants to verify the current Gatekeeper assessment status of a downloaded app at /Users/analyst/Downloads/Tool.app. Which command should the administrator use to perform this check?
8A compliance officer wants to confirm that full disk encryption is active on a MacBook so that data at rest is protected if the device is lost. Which command should the officer run to check the FileVault status?
9A security analyst is investigating a macOS Monterey system that may have been compromised. The analyst wants to check for signs of malicious kernel extensions. Which TWO of the following commands or tools are most appropriate for this task? (Choose two.)
10A security administrator is configuring a macOS Big Sur endpoint to meet a compliance requirement that mandates all system extensions must be explicitly approved by the user. Which command should the administrator use to verify that only approved system extensions are loaded?
Be able to run and interpret csrutil status, spctl --assess, kextstat, and systemextensionsctl output, then map results to the right control. The critical skill is distinguishing which macOS security layer is actually responsible for a given block or finding.
The Courseiva GSEC question bank contains 10 questions in the macOS Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the macOS Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included