Courseiva

GSEC · domain

macOS Security

This domain covers macOS platform hardening and threat detection as tested on the GSEC exam: Gatekeeper, notarization, System Integrity Protection, kernel extension controls, FileVault, and the command-line tools used to inspect them. Questions present real command output or a security requirement and ask you to interpret the posture or select the correct control.

10 questions2 easy6 medium2 hard

Focused practice

Practice macOS Security questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about macOS Security

Be able to run and interpret csrutil status, spctl --assess, kextstat, and systemextensionsctl output, then map results to the right control. The critical skill is distinguishing which macOS security layer is actually responsible for a given block or finding.

Interpreting Gatekeeper and notarization behavior when a downloaded app is blocked from launching

System Integrity Protection (SIP) and its role in preventing unauthorized kernel and system modifications

Using kextstat, kmutil, and systemextensionsctl to enumerate kernel extensions and system extensions

Reading spctl, csrutil, and codesign output to assess code-signing and security configuration state

Watch out for

Common macOS Security exam traps

  • ▸Confusing Gatekeeper (app launch policy) with notarization (Apple malware scan) and XProtect (signature-based detection) when identifying the blocking control
  • ▸Assuming SIP can be disabled at will; it requires booting to Recovery and running csrutil disable, and status must be verified with csrutil status
  • ▸Treating all kernel extensions as malicious; Apple-signed and user-approved kexts are legitimate, so check signing and approval state before flagging

Question index

All macOS Security questions (10)

Click any question to see the full explanation, or start a practice session above.

1

A user reports they cannot open a downloaded application because macOS states the developer cannot be verified. Which security feature is preventing the execution of this application?

Medium
2

A compliance officer wants to confirm that full disk encryption is active on a MacBook so that data at rest is protected if the device is lost. Which command should the officer run to check the FileVault status?

Easy
3

A user attempts to launch a newly installed application on a macOS Monterey system, but the application fails to open with a message that it cannot be verified. The user is certain the application was downloaded from the developer's official website. Which macOS feature is responsible for this behavior?

Easy
4

What is the primary purpose of the 'Notarization' process for macOS applications?

Medium
5

Which TWO of the following actions are primarily restricted by macOS System Integrity Protection (SIP)?

Hard
6

Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretation regarding the security posture of this endpoint?

Medium
7

A security administrator is configuring a macOS Big Sur endpoint to meet a compliance requirement that mandates all system extensions must be explicitly approved by the user. Which command should the administrator use to verify that only approved system extensions are loaded?

Hard
8

A security analyst is investigating a macOS Monterey system that may have been compromised. The analyst wants to check for signs of malicious kernel extensions. Which TWO of the following commands or tools are most appropriate for this task? (Choose two.)

Medium
9

A security administrator is configuring a macOS fleet to enforce that only apps signed with an Apple-issued Developer ID certificate and notarized by Apple can run. The administrator wants to verify the current Gatekeeper assessment status of a downloaded app at /Users/analyst/Downloads/Tool.app. Which command should the administrator use to perform this check?

Medium
10

An organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?

Medium

Frequently asked questions

What does the macOS Security domain cover on the GSEC exam?
Be able to run and interpret csrutil status, spctl --assess, kextstat, and systemextensionsctl output, then map results to the right control. The critical skill is distinguishing which macOS security layer is actually responsible for a given block or finding.
How many questions are in this domain?
This page lists all 10 macOS Security questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only macOS Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC macos security Practice Questions