← All ACSP Flashcard Decks

macOS Platform Security (Gatekeeper, SIP, Notarization, XProtect) Flashcards

6 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 macOS Platform Security (Gatekeeper, SIP, Notarization, XProtect) flashcards as text
  1. What is the primary purpose of Gatekeeper in macOS?

    Answer: To verify that apps come from identified developers and have not been tampered with before allowing them to run

    Gatekeeper checks apps against Apple's requirements for identified Developer ID signatures and notarization. It prevents apps from unknown or unverified sources from launching without explicit user override, acting as the first line of defense against malicious software at the point of execution.

  2. What does Apple's notarization service verify when a developer submits an app?

    Answer: That the app is signed with a valid Developer ID and has been scanned for known malware

    Apple's notarization process is automated: it scans the submitted app for known malware and verifies it carries a valid Developer ID signature. It does not involve human code review. Once approved, a notarization ticket is stapled to the app so Gatekeeper can verify it offline.

  3. A technician must disable System Integrity Protection (SIP) on an Intel-based Mac to install a low-level kernel extension. What is the correct procedure?

    Answer: Boot into macOS Recovery (Command-R at startup), then run 'csrutil disable' in Terminal

    SIP can only be modified from the macOS Recovery environment (reached by holding Command-R during startup on Intel Macs, or holding the power button on Apple silicon). Running 'csrutil disable' from a normal booted session — even as root — has no effect because SIP is enforced before the OS fully loads.

  4. Which of the following actions does System Integrity Protection (SIP) prevent, even when executed with root or sudo privileges?

    Answer: Modifying files located in /System, /usr, /bin, and /sbin

    SIP marks critical system directories — /System, /usr, /bin, /sbin, and pre-installed Apple apps — as read-only for all processes, including root. This prevents malware or poorly-written software from corrupting core OS components. User-installed apps in /Applications and user data are not restricted by SIP.

  5. A user on a Mac attempts to open a downloaded app that has not been notarized. What is the default Gatekeeper behavior on modern macOS?

    Answer: macOS refuses to open the app and displays an alert stating it cannot be checked for malicious software

    By default, Gatekeeper blocks unnotarized apps and shows a dialog saying the app 'cannot be checked for malicious software.' The user can override this only by going to System Settings > Privacy & Security and explicitly clicking 'Open Anyway' — a deliberate, non-default action required each time.

  6. What is the primary function of XProtect in macOS?

    Answer: Scanning downloaded files and launched apps against a database of known malware signatures

    XProtect is Apple's built-in, signature-based anti-malware engine. It automatically scans files when they are first downloaded or opened and compares them against an Apple-maintained database of known malware signatures. Apple silently updates XProtect signatures independently of macOS system updates.