Courseiva

GSEC · topic practice

macOS Security practice questions

This domain covers macOS platform hardening and threat detection as tested on the GSEC exam: Gatekeeper, notarization, System Integrity Protection, kernel extension controls, FileVault, and the command-line tools used to inspect them. Questions present real command output or a security requirement and ask you to interpret the posture or select the correct control.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
19 questionsDomain: macOS Security

What the exam tests

What to know about macOS Security

Be able to run and interpret csrutil status, spctl --assess, kextstat, and systemextensionsctl output, then map results to the right control. The critical skill is distinguishing which macOS security layer is actually responsible for a given block or finding.

Interpreting Gatekeeper and notarization behavior when a downloaded app is blocked from launching

System Integrity Protection (SIP) and its role in preventing unauthorized kernel and system modifications

Using kextstat, kmutil, and systemextensionsctl to enumerate kernel extensions and system extensions

Reading spctl, csrutil, and codesign output to assess code-signing and security configuration state

Watch out for

Common macOS Security exam traps

  • ▸Confusing Gatekeeper (app launch policy) with notarization (Apple malware scan) and XProtect (signature-based detection) when identifying the blocking control
  • ▸Assuming SIP can be disabled at will; it requires booting to Recovery and running csrutil disable, and status must be verified with csrutil status
  • ▸Treating all kernel extensions as malicious; Apple-signed and user-approved kexts are legitimate, so check signing and approval state before flagging

Practice set

macOS Security questions

19 questions · select your answer, then reveal the explanation

A security analyst is investigating a macOS endpoint that appears to have an unauthorized kernel extension loaded. Which command-line utility should the analyst use to list currently loaded kernel extensions to verify if the extension is properly signed?

Which security framework is primarily responsible for managing the 'App Sandbox' on macOS, preventing applications from accessing files outside their designated container?

Which THREE of the following are examples of macOS TCC (Transparency, Consent, and Control) protection categories?

Question 4mediummultiple choice
Read the full macOS Security explanation →

A security analyst is reviewing a macOS Ventura endpoint and needs to determine whether Full Disk Access has been granted to a third-party backup agent. The analyst has Terminal access but wants to avoid changing any system state. Which command should the analyst run to inspect the TCC database entry for the backup agent?

A Mac administrator wants to ensure that only Apple-signed and notarized software can execute on managed endpoints, blocking any unsigned binaries even when downloaded from the internet. Which macOS configuration most directly enforces this requirement?

Question 6mediummultiple choice
Read the full macOS Security explanation →

A security administrator is reviewing a macOS Ventura endpoint and wants to confirm which security policies are currently enforced by the Secure Enclave. Which command-line utility should be used to display the current security configuration, including Secure Enclave status?

A security engineer is hardening a fleet of Mac computers running macOS Ventura. The engineer wants to ensure that only trusted kernel extensions can load. Which command should be used to check the current kernel extension policy on an Apple silicon Mac?

Question 8mediummultiple choice
Read the full macOS Security explanation →

A security team is tuning endpoint detection on macOS and wants to monitor authentication events, including failed sudo attempts and login failures, in a centralized log pipeline. The team plans to stream relevant events from the unified logging system. Which command should the team use to capture authentication-related log entries in real time?

A security analyst is examining a macOS Ventura endpoint that is suspected of having a malicious background service. The analyst runs `launchctl print system/com.apple.securityd` and sees the service is loaded, but when checking `/System/Library/LaunchDaemons/com.apple.securityd.plist`, the file is present. However, the analyst also notices a suspicious `com.apple.securityd.plist` file in `/Library/LaunchDaemons/`. Which of the following best describes the security implication and the correct action?

Question 10mediummultiple choice
Read the full macOS Security explanation →

An organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?

Which TWO of the following actions are primarily restricted by macOS System Integrity Protection (SIP)?

Question 12mediummultiple choice
Read the full macOS Security explanation →

Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretation regarding the security posture of this endpoint?

Exhibit

csrutil status
System Integrity Protection status: enabled.
Question 13mediummultiple choice
Read the full macOS Security explanation →

A user reports they cannot open a downloaded application because macOS states the developer cannot be verified. Which security feature is preventing the execution of this application?

Question 14mediummultiple choice
Read the full macOS Security explanation →

What is the primary purpose of the 'Notarization' process for macOS applications?

Question 15easymultiple choice
Read the full macOS Security explanation →

A user attempts to launch a newly installed application on a macOS Monterey system, but the application fails to open with a message that it cannot be verified. The user is certain the application was downloaded from the developer's official website. Which macOS feature is responsible for this behavior?

Question 16mediummultiple choice
Read the full macOS Security explanation →

A security administrator is configuring a macOS fleet to enforce that only apps signed with an Apple-issued Developer ID certificate and notarized by Apple can run. The administrator wants to verify the current Gatekeeper assessment status of a downloaded app at /Users/analyst/Downloads/Tool.app. Which command should the administrator use to perform this check?

Question 17easymultiple choice
Read the full macOS Security explanation →

A compliance officer wants to confirm that full disk encryption is active on a MacBook so that data at rest is protected if the device is lost. Which command should the officer run to check the FileVault status?

A security analyst is investigating a macOS Monterey system that may have been compromised. The analyst wants to check for signs of malicious kernel extensions. Which TWO of the following commands or tools are most appropriate for this task? (Choose two.)

Question 19hardmultiple choice
Read the full macOS Security explanation →

A security administrator is configuring a macOS Big Sur endpoint to meet a compliance requirement that mandates all system extensions must be explicitly approved by the user. Which command should the administrator use to verify that only approved system extensions are loaded?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused macOS Security sessions

Start a macOS Security only practice session

Every question in these sessions is drawn from the macOS Security domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about macOS Security?
Be able to run and interpret csrutil status, spctl --assess, kextstat, and systemextensionsctl output, then map results to the right control. The critical skill is distinguishing which macOS security layer is actually responsible for a given block or finding.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just macOS Security questions in a focused session?
Yes — the session launcher on this page draws every question from the macOS Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.