GSEC macOS Security Practice Question
An organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?
⚠ Common exam trap
Candidates frequently mistake Gatekeeper or XProtect for SIP, failing to recognize that SIP is specifically the mechanism that enforces kernel-level integrity and prevents root-level modifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System Integrity Protection (SIP)
System Integrity Protection (SIP) is the macOS feature designed to restrict the root user from performing actions that could compromise system integrity. By enforcing kernel-level protection, SIP prevents malicious code from injecting into system processes or modifying protected files. Understanding SIP is critical for GSEC candidates as it represents the foundational boundary between user-space applications and sensitive kernel operations, serving as a primary defense against rootkits and low-level system tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FileVault 2
Why it's wrong here
FileVault 2 provides full-disk encryption for the macOS volume. While essential for data confidentiality against physical theft, it does not manage kernel-level integrity or prevent unauthorized modifications to system binaries. It focuses solely on protecting stored data at rest rather than executing code integrity verification.
- ✗
Gatekeeper
Why it's wrong here
Gatekeeper is a verification mechanism that checks if software is digitally signed by a trusted developer before it is allowed to run. While it protects the system from installing untrusted user-space applications, it operates at a higher level and does not enforce kernel-level integrity protections like SIP.
- ✓
System Integrity Protection (SIP)
Why this is correct
System Integrity Protection restricts the root user from modifying protected locations like /System, /bin, and /usr. By enforcing signed kernel extensions and preventing unauthorized modifications to system processes, it directly protects the kernel integrity, ensuring that only trusted, Apple-approved code can operate at the system core level.
- ✗
XProtect
Why it's wrong here
XProtect is a built-in macOS signature-based antivirus technology that scans files when they are downloaded or opened. It operates as a reactive malware scanner rather than a proactive kernel-level enforcement mechanism. It does not prevent unauthorized modifications to system files or kernel space in the way SIP does.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.