Risk Management & Mitigation Flashcards
7 cards from real ACT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
An organization's MDM profile is accidentally pushed to unintended devices during a training demonstration. Which principle, if applied, would have limited the impact?
Answer: Principle of least privilege — profiles scoped only to designated test devices
The principle of least privilege limits profile deployment to only the necessary devices, reducing the blast radius of accidental pushes.
A trainer plans to demonstrate Apple Configurator 2 by erasing a participant's iPhone as an example. What risk management step is essential before proceeding?
Answer: Verify the participant has a full backup and understands the device will be wiped
Erasing a device without a verified backup creates risk of permanent data loss, so backup confirmation is mandatory before any erase demonstration.
During a session on Activation Lock, a participant's device becomes Activation Locked and they cannot remember their Apple ID. What is the correct risk-aware response?
Answer: Direct the participant to Apple Support and continue training on another device
Only Apple Support can assist with legitimate Activation Lock removal; bypassing it with third-party tools is both a security risk and potentially illegal.
A corporation wants trainers to use screen recording during live sessions for compliance documentation. What privacy risk must be addressed?
Answer: Recordings may capture sensitive participant data such as passwords or personal information
Screen recordings during live sessions can inadvertently capture passwords, personal data, or confidential information, creating privacy and compliance risks.
Which approach best mitigates the risk of a misconfigured MDM payload disrupting all enrolled devices at a client site?
Answer: Test payloads on a small pilot group before organization-wide deployment
Piloting payloads on a small test group catches configuration errors before they can impact the entire device fleet.
A training participant shares their Apple School Manager login credentials with a colleague who missed the session. What risk does this create?
Answer: Credential sharing violates account security and creates an unauditable access trail
Sharing credentials undermines account security, makes audit logs unreliable, and violates institutional access policies.
A trainer notices that participant Macs have System Integrity Protection (SIP) disabled before the session. What risk does this present?
Answer: Disabled SIP exposes core system files to accidental or malicious modification
SIP protects critical macOS system files; disabling it leaves the operating system vulnerable to corruption or malicious modification.