GSEC macOS Security Practice Question
A security administrator is configuring a macOS fleet to enforce that only apps signed with an Apple-issued Developer ID certificate and notarized by Apple can run. The administrator wants to verify the current Gatekeeper assessment status of a downloaded app at /Users/analyst/Downloads/Tool.app. Which command should the administrator use to perform this check?
⚠ Common exam trap
The trap here is assuming that verifying the code signature with codesign proves Gatekeeper will allow the app, when signature integrity and Gatekeeper policy are separate checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spctl --assess --type execute --verbose /Users/analyst/Downloads/Tool.app
Gatekeeper assessment is performed by the spctl utility, which consults system policy to decide whether an app is permitted to execute. Running spctl with the assess action, the execute type, and verbose output against the target app returns an acceptance or rejection verdict along with the reason, which directly reflects Developer ID signing and notarization requirements enforced on the endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
xattr -l /Users/analyst/Downloads/Tool.app
Why it's wrong here
xattr -l lists extended attributes such as com.apple.quarantine that may be present on downloaded files, but it only shows metadata and does not perform a Gatekeeper policy evaluation. Seeing a quarantine attribute does not confirm whether the app is notarized or whether Gatekeeper would accept it for execution.
- ✗
codesign --verify --deep --strict /Users/analyst/Downloads/Tool.app
Why it's wrong here
codesign --verify validates the cryptographic integrity of the code signature and resource envelope, but it does not evaluate Gatekeeper policy or notarization status. An app can pass codesign verification while still being blocked by Gatekeeper because it lacks a Developer ID signature or a notarization ticket, so this command does not answer the assessment question.
- ✗
system_profiler SPApplicationsDataType
Why it's wrong here
system_profiler SPApplicationsDataType enumerates installed applications and reports metadata like version, obtained date, and signing information, but it is an inventory report rather than a policy assessment. It does not evaluate whether a specific app would be allowed to run under the current Gatekeeper configuration, so it cannot verify the assessment status.
- ✓
spctl --assess --type execute --verbose /Users/analyst/Downloads/Tool.app
Why this is correct
The spctl command is the system policy control tool that evaluates Gatekeeper assessments. Using --assess with --type execute and --verbose against the app path returns whether the app is accepted by Gatekeeper and the reason for rejection, directly confirming notarization and Developer ID signing status for the specified app.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.