Courseiva
macOS Security →mediumMultiple Choice

GSEC macOS Security Practice Question

A security administrator is configuring a macOS fleet to enforce that only apps signed with an Apple-issued Developer ID certificate and notarized by Apple can run. The administrator wants to verify the current Gatekeeper assessment status of a downloaded app at /Users/analyst/Downloads/Tool.app. Which command should the administrator use to perform this check?

⚠ Common exam trap

The trap here is assuming that verifying the code signature with codesign proves Gatekeeper will allow the app, when signature integrity and Gatekeeper policy are separate checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

spctl --assess --type execute --verbose /Users/analyst/Downloads/Tool.app

Gatekeeper assessment is performed by the spctl utility, which consults system policy to decide whether an app is permitted to execute. Running spctl with the assess action, the execute type, and verbose output against the target app returns an acceptance or rejection verdict along with the reason, which directly reflects Developer ID signing and notarization requirements enforced on the endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    xattr -l /Users/analyst/Downloads/Tool.app

    Why it's wrong here

    xattr -l lists extended attributes such as com.apple.quarantine that may be present on downloaded files, but it only shows metadata and does not perform a Gatekeeper policy evaluation. Seeing a quarantine attribute does not confirm whether the app is notarized or whether Gatekeeper would accept it for execution.

  • ✗

    codesign --verify --deep --strict /Users/analyst/Downloads/Tool.app

    Why it's wrong here

    codesign --verify validates the cryptographic integrity of the code signature and resource envelope, but it does not evaluate Gatekeeper policy or notarization status. An app can pass codesign verification while still being blocked by Gatekeeper because it lacks a Developer ID signature or a notarization ticket, so this command does not answer the assessment question.

  • ✗

    system_profiler SPApplicationsDataType

    Why it's wrong here

    system_profiler SPApplicationsDataType enumerates installed applications and reports metadata like version, obtained date, and signing information, but it is an inventory report rather than a policy assessment. It does not evaluate whether a specific app would be allowed to run under the current Gatekeeper configuration, so it cannot verify the assessment status.

  • ✓

    spctl --assess --type execute --verbose /Users/analyst/Downloads/Tool.app

    Why this is correct

    The spctl command is the system policy control tool that evaluates Gatekeeper assessments. Using --assess with --type execute and --verbose against the app path returns whether the app is accepted by Gatekeeper and the reason for rejection, directly confirming notarization and Developer ID signing status for the specified app.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.