Courseiva
macOS Security →easyMultiple Choice

GSEC macOS Security Practice Question

A compliance officer wants to confirm that full disk encryption is active on a MacBook so that data at rest is protected if the device is lost. Which command should the officer run to check the FileVault status?

⚠ Common exam trap

A common mix-up: candidates confuse volume-level APFS encryption reporting from diskutil with the user-facing FileVault configuration that fdesetup reports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fdesetup status

FileVault is macOS full disk encryption, and its state is queried with the fdesetup utility. Running fdesetup status returns whether encryption is on, off, or in progress, which is precisely the evidence a compliance officer needs to confirm data-at-rest protection. Other tools report unrelated security features such as SIP or Gatekeeper.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    fdesetup status

    Why this is correct

    fdesetup status reports whether FileVault is On or Off and, when in progress, the percentage of encryption completed. It directly answers the compliance question about full disk encryption being active on the MacBook, making it the correct tool for verifying FileVault state.

  • ✗

    csrutil status

    Why it's wrong here

    csrutil status reports the System Integrity Protection configuration, which protects system files and processes from modification. It is unrelated to disk encryption and provides no indication of whether FileVault is enabled, so it cannot satisfy the compliance check for data-at-rest protection.

  • ✗

    spctl --status

    Why it's wrong here

    spctl --status reports whether Gatekeeper assessments are enabled or disabled. It governs application execution policy, not disk encryption, and therefore gives no information about FileVault or the protection of data at rest on the lost device scenario.

  • ✗

    diskutil apfs list

    Why it's wrong here

    diskutil apfs list enumerates APFS containers and volumes, showing encryption status of individual volumes, but it does not report whether FileVault is enabled for the user account or whether the volume is unlocked at boot. It provides storage layout detail rather than the FileVault configuration state the officer needs.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.