Courseiva
macOS Security →mediumMultiple Choice

GSEC macOS Security Practice Question

A user reports they cannot open a downloaded application because macOS states the developer cannot be verified. Which security feature is preventing the execution of this application?

⚠ Common exam trap

Candidates often confuse Gatekeeper with XProtect or FileVault, mixing up the application verification framework with antivirus signatures or disk encryption technologies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Gatekeeper

Gatekeeper is the security technology that verifies that software is from a trusted developer and has not been tampered with. By requiring code signing and notarization, Gatekeeper helps prevent the execution of malicious software. For a GSEC professional, recognizing Gatekeeper's role is key to troubleshooting deployment issues while maintaining the organization's security policy, as it is the first line of defense against unauthorized applications running on the user's desktop.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    XProtect

    Why it's wrong here

    XProtect acts as a signature-based scanner for known malware. It does not block applications based on the status of their developer signature or notarization status. Instead, it checks files against a list of known malicious signatures to prevent known threats from launching on the system.

  • ✓

    Gatekeeper

    Why this is correct

    Gatekeeper is the security feature that checks if an application is signed by an identified developer and notarized by Apple. If an application fails these checks, Gatekeeper prevents it from executing to ensure that the software has not been altered or created by an untrusted entity.

  • ✗

    System Integrity Protection

    Why it's wrong here

    System Integrity Protection restricts modifications to the system itself, such as /System and /usr. It does not perform verification on downloaded third-party user applications. Therefore, it has no role in preventing the execution of a user-level application based on its developer identity or signature.

  • ✗

    FileVault 2

    Why it's wrong here

    FileVault 2 is responsible for encrypting the startup disk to protect data at rest. It does not have any functionality related to validating code signatures or developer identities for applications. It operates at the storage layer, not the application execution layer, and thus is unrelated here.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.