GSEC macOS Security Practice Question
A compliance officer wants to confirm that full disk encryption is active on a MacBook so that data at rest is protected if the device is lost. Which command should the officer run to check the FileVault status?
⚠ Common exam trap
A common mix-up: candidates confuse volume-level APFS encryption reporting from diskutil with the user-facing FileVault configuration that fdesetup reports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
fdesetup status
FileVault is macOS full disk encryption, and its state is queried with the fdesetup utility. Running fdesetup status returns whether encryption is on, off, or in progress, which is precisely the evidence a compliance officer needs to confirm data-at-rest protection. Other tools report unrelated security features such as SIP or Gatekeeper.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
fdesetup status
Why this is correct
fdesetup status reports whether FileVault is On or Off and, when in progress, the percentage of encryption completed. It directly answers the compliance question about full disk encryption being active on the MacBook, making it the correct tool for verifying FileVault state.
- ✗
csrutil status
Why it's wrong here
csrutil status reports the System Integrity Protection configuration, which protects system files and processes from modification. It is unrelated to disk encryption and provides no indication of whether FileVault is enabled, so it cannot satisfy the compliance check for data-at-rest protection.
- ✗
spctl --status
Why it's wrong here
spctl --status reports whether Gatekeeper assessments are enabled or disabled. It governs application execution policy, not disk encryption, and therefore gives no information about FileVault or the protection of data at rest on the lost device scenario.
- ✗
diskutil apfs list
Why it's wrong here
diskutil apfs list enumerates APFS containers and volumes, showing encryption status of individual volumes, but it does not report whether FileVault is enabled for the user account or whether the volume is unlocked at boot. It provides storage layout detail rather than the FileVault configuration state the officer needs.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.