GSEC macOS Security Practice Question
A security analyst is investigating a macOS Monterey system that may have been compromised. The analyst wants to check for signs of malicious kernel extensions. Which TWO of the following commands or tools are most appropriate for this task? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse system extensions with kernel extensions; systemextensionsctl list does not show kernel extensions, and csrutil or spctl do not list loaded kexts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kmutil showloaded
To check for malicious kernel extensions, an analyst should use tools that list loaded kexts. The kextstat command provides a list of loaded kernel extensions, while kmutil showloaded offers similar information with more detail. Both are appropriate for identifying unauthorized kexts. The other commands focus on system extensions, SIP status, or Gatekeeper assessments, which do not directly reveal loaded kernel extensions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kmutil showloaded
Why this is correct
The kmutil showloaded command displays information about currently loaded kernel extensions and other kernel collections. It is a modern replacement for kextstat and provides detailed output that can help identify unauthorized or malicious kexts. It is an appropriate tool for investigating kernel-level compromise on macOS.
- ✗
spctl --assess --verbose
Why it's wrong here
The spctl --assess --verbose command evaluates the Gatekeeper assessment of an application or bundle. It does not list kernel extensions or provide information about loaded kexts. This command is used to check if an app is allowed to run, not to inspect kernel-level components. Thus, it is irrelevant for detecting malicious kernel extensions.
- ✓
kextstat
Why this is correct
The kextstat command lists all currently loaded kernel extensions along with their load addresses, sizes, and versions. This allows an analyst to identify any unexpected or unsigned kernel extensions that may indicate a compromise. It is a standard tool for examining the kernel extension landscape on macOS, making it appropriate for this investigation.
- ✗
systemextensionsctl list
Why it's wrong here
The systemextensionsctl list command shows installed system extensions and their approval status. System extensions are a newer mechanism that runs in user space, not kernel space. While they can be malicious, they are not kernel extensions. This command does not list kernel extensions, so it is not the best tool for checking for malicious kexts.
- ✗
csrutil status
Why it's wrong here
The csrutil status command checks whether System Integrity Protection is enabled. While SIP helps prevent unauthorized kernel extensions, this command only reports the SIP status. It does not list loaded kernel extensions or identify malicious ones. Therefore, it is not directly useful for detecting malicious kexts.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.