CCA CCA User Management and Privileges 1 — Questions and Answers
Question 1: In Jamf Pro, which feature allows you to bind a Mac to Active Directory so users can log in with their AD credentials?
- Directory Binding via a Configuration Profile or policy (Correct answer)
- LDAP server configuration only
- Local account creation script
- Keychain sync
Correct answer: Directory Binding via a Configuration Profile or policy
Jamf Pro can bind Macs to Active Directory using a Directory Binding payload in a Configuration Profile or via a policy, enabling AD login.
Question 2: What Jamf Pro management account is automatically created on enrolled Macs and used by the Jamf binary to perform privileged operations?
- The Jamf management account (often named 'jamfadmin') (Correct answer)
- The built-in macOS root account
- The first local admin user
- The MDM enrollment user
Correct answer: The Jamf management account (often named 'jamfadmin')
Jamf Pro creates a local management account (typically named 'jamfadmin') with admin privileges on enrolled Macs to perform management tasks.
Question 3: How does Jamf Pro's 'Local Accounts' policy payload help with user management?
- It creates, modifies, or deletes local user accounts on managed Macs (Correct answer)
- It syncs iCloud accounts to managed Macs
- It enables FileVault for user accounts
- It imports users from Active Directory
Correct answer: It creates, modifies, or deletes local user accounts on managed Macs
The Local Accounts policy payload in Jamf Pro lets admins create new local accounts, change passwords, reset home directories, or delete accounts on managed devices.
Question 4: Which Jamf Pro feature allows you to grant a standard user temporary admin rights for a specified duration without permanently elevating their account?
- Privilege Escalation via a Self Service policy that grants then revokes admin rights (Correct answer)
- Permanently modifying the local account type
- Creating a separate admin account
- Using sudo without a password
Correct answer: Privilege Escalation via a Self Service policy that grants then revokes admin rights
You can build a Self Service policy that temporarily elevates a user to admin and a complementary policy that revokes those rights after a set period.
Question 5: In Jamf Pro, what is an LDAP server connection used for?
- Authenticating Jamf Pro users and scoping policies by directory group membership (Correct answer)
- Syncing device inventory to Active Directory
- Pushing certificates to managed Macs
- Creating mobile device enrollment profiles
Correct answer: Authenticating Jamf Pro users and scoping policies by directory group membership
Connecting Jamf Pro to an LDAP server allows admin login via directory credentials and enables scoping of policies/profiles to specific directory groups.
Question 6: What macOS mechanism does Jamf Pro use to enforce that only approved software can be launched by standard users?
- Gatekeeper + allowed/blocked process policy payloads (Correct answer)
- FileVault encryption
- System Integrity Protection
- Parental Controls
Correct answer: Gatekeeper + allowed/blocked process policy payloads
Jamf Pro can configure Gatekeeper settings via configuration profiles and use allowed/blocked process payloads in policies to restrict which apps standard users can run.
In Jamf Pro, which feature allows you to bind a Mac to Active Directory so users can log in with their AD credentials?