Courseiva
macOS Security →hardMultiple Select

GSEC macOS Security Practice Question

Which TWO of the following actions are primarily restricted by macOS System Integrity Protection (SIP)?

⚠ Common exam trap

Candidates often assume SIP restricts user-space application installation, whereas SIP specifically targets system-level modifications and kernel extensions to prevent deep OS-level compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modifying files within the /System directory

SIP is a crucial security layer that limits root user capabilities to prevent system-level damage. By restricting modifications to protected system directories and kernel extensions, it effectively hardens the operating system against exploitation. For GSEC professionals, identifying what SIP protects is vital for performing system audits, troubleshooting software installations, and managing secure configurations, as these restrictions often impact how security agents and administrative tools interact with the underlying OS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Modifying files within the /System directory

    Why this is correct

    The /System directory contains core macOS components that are essential for system stability and security. SIP explicitly prevents the root user from writing to or modifying files in this path, ensuring that core binaries and libraries remain untampered throughout the lifecycle of the operating system.

  • ✗

    Installing unsigned applications from the internet

    Why it's wrong here

    Gatekeeper, not SIP, governs the installation of unsigned applications. Gatekeeper performs code signing checks upon execution or disk image mounting. While SIP protects system-level files, the decision to allow or block the installation of third-party, non-Apple-signed applications is handled by policy controls within the Gatekeeper sub-system.

  • ✓

    Loading unsigned kernel extensions (kexts)

    Why this is correct

    SIP mandates that only kernel extensions signed by a valid Apple Developer ID may be loaded. This prevents malicious actors from loading unsigned rootkits or drivers that could bypass security controls. By enforcing cryptographic signatures for kexts, the system maintains a secure chain of trust at the kernel level.

  • ✗

    Accessing user-defined keychain items

    Why it's wrong here

    Keychain access is managed by the Security framework and user authorization prompts, not SIP. SIP focuses on protecting the operating system files and kernel state, whereas Keychain access control is a separate logical layer designed to protect sensitive user credentials and cryptographic keys from unauthorized process access.

  • ✗

    Encrypting the user home directory

    Why it's wrong here

    Home directory encryption is managed by FileVault 2, which provides transparent, volume-level encryption for the startup disk. SIP is an integrity mechanism rather than a data-at-rest protection service, and thus has no functional role in the encryption of user home directories or disk volumes.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.