GSEC macOS Security Practice Question
A security administrator is configuring a macOS Big Sur endpoint to meet a compliance requirement that mandates all system extensions must be explicitly approved by the user. Which command should the administrator use to verify that only approved system extensions are loaded?
⚠ Common exam trap
The trap here is conflating system extensions with kernel extensions; systemextensionsctl list is the correct tool for system extensions, while kextstat is for kernel extensions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
systemextensionsctl list
System extensions are a modern replacement for kernel extensions and require user approval before they can load. The systemextensionsctl list command provides a detailed list of all system extensions along with their approval status. This allows administrators to verify that only approved extensions are present, meeting the compliance requirement. The other commands either list kernel extensions or check different security features, so they do not provide the needed information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
systemextensionsctl list
Why this is correct
The systemextensionsctl list command displays all installed system extensions and indicates whether each is approved by the user or pending approval. This directly addresses the compliance requirement to verify that only approved system extensions are loaded. It provides the necessary status information to confirm user approval.
- ✗
csrutil status
Why it's wrong here
The csrutil status command reports the status of System Integrity Protection. SIP restricts modifications to protected system files, but it does not manage or report on system extension approvals. This command is unrelated to the task of verifying approved system extensions.
- ✗
spctl --status
Why it's wrong here
The spctl --status command checks whether Gatekeeper is enabled. Gatekeeper controls application execution, not system extension approval. It does not provide any information about system extensions or their approval status. Therefore, it is not useful for this verification task.
- ✗
kextstat
Why it's wrong here
The kextstat command lists loaded kernel extensions, not system extensions. System extensions are different from kernel extensions; they run in user space and are managed separately. This command does not show approval status for system extensions, so it cannot verify the compliance requirement.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.