Courseiva
easyMultiple ChoiceObjective-mapped

220-1202 Practice Question: A school IT administrator needs to remotely lock…

A school IT administrator needs to remotely lock a lost MacBook and display a custom message with contact information. The MacBook is enrolled in the school’s MDM and has an internet connection. Which macOS feature should they use?

⚠ Common exam trap

The A+ exam often tests the distinction between remote management tools (like Remote Desktop) and dedicated lost-device recovery features (like Find My Mac). Candidates may mistakenly assume that any remote access tool can perform the lock-and-message function, but only Find My Mac provides the specific lost-mode lock with custom message display.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Find My Mac

Find My Mac is the correct feature because it is specifically designed to locate, lock, and display a custom message on a lost Apple device that is enrolled in MDM and connected to the internet. It leverages Apple's Activation Lock and MDM integration to remotely lock the Mac and present a contact message on the Lock screen, fulfilling the administrator's requirement without needing physical access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remote Desktop

    Why it's wrong here

    Remote Desktop, specifically Apple Remote Desktop (ARD), is a macOS application designed for remote management of other Macs, typically within the same local area network or via VPN. It enables IT administrators to perform software distribution, asset management, and remote assistance by directly controlling the desktop. However, ARD does not provide lost device tracking, remote locking capabilities for a missing device, or location services, making it unsuitable for securing a lost or stolen Mac outside of the managed network.

  • Find My Mac

    Why this is correct

    Find My Mac is the correct solution as it is an integrated Apple service designed specifically for locating and securing lost or stolen macOS devices. When enabled, it leverages iCloud to allow an administrator to remotely lock the device with a passcode, display a custom message on the lock screen, play a sound, or even erase all data to protect sensitive information. This functionality relies on the device having an active internet connection and being linked to an iCloud account, providing essential anti-theft and data protection features.

  • FileVault

    Why it's wrong here

    FileVault is a full-disk encryption feature built into macOS that encrypts the entire startup disk to protect data at rest from unauthorized access. While crucial for data security, FileVault operates locally on the device and does not offer any remote management capabilities, such as locking a lost device, tracking its location, or displaying a message. Its sole purpose is to render the data unreadable without the correct decryption key, not to provide anti-theft or recovery services.

  • Terminal command 'sudo pmset'

    Why it's wrong here

    The Terminal command 'sudo pmset' is a command-line utility in macOS used to control and configure power management settings for the system. This includes managing sleep modes, display sleep, hard disk spin-down, and other power-related behaviors. It is a local administrative tool and has no functionality for remotely locking a device, tracking its location, or interacting with any anti-theft services. Therefore, it is entirely unrelated to the task of securing a lost Mac.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.