Courseiva
macOS Security →mediumMultiple Choice

GSEC macOS Security Practice Question

An organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?

⚠ Common exam trap

Candidates frequently mistake Gatekeeper or XProtect for SIP, failing to recognize that SIP is specifically the mechanism that enforces kernel-level integrity and prevents root-level modifications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System Integrity Protection (SIP)

System Integrity Protection (SIP) is the macOS feature designed to restrict the root user from performing actions that could compromise system integrity. By enforcing kernel-level protection, SIP prevents malicious code from injecting into system processes or modifying protected files. Understanding SIP is critical for GSEC candidates as it represents the foundational boundary between user-space applications and sensitive kernel operations, serving as a primary defense against rootkits and low-level system tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FileVault 2

    Why it's wrong here

    FileVault 2 provides full-disk encryption for the macOS volume. While essential for data confidentiality against physical theft, it does not manage kernel-level integrity or prevent unauthorized modifications to system binaries. It focuses solely on protecting stored data at rest rather than executing code integrity verification.

  • ✗

    Gatekeeper

    Why it's wrong here

    Gatekeeper is a verification mechanism that checks if software is digitally signed by a trusted developer before it is allowed to run. While it protects the system from installing untrusted user-space applications, it operates at a higher level and does not enforce kernel-level integrity protections like SIP.

  • ✓

    System Integrity Protection (SIP)

    Why this is correct

    System Integrity Protection restricts the root user from modifying protected locations like /System, /bin, and /usr. By enforcing signed kernel extensions and preventing unauthorized modifications to system processes, it directly protects the kernel integrity, ensuring that only trusted, Apple-approved code can operate at the system core level.

  • ✗

    XProtect

    Why it's wrong here

    XProtect is a built-in macOS signature-based antivirus technology that scans files when they are downloaded or opened. It operates as a reactive malware scanner rather than a proactive kernel-level enforcement mechanism. It does not prevent unauthorized modifications to system files or kernel space in the way SIP does.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.