Jamf Certified Casper Administrator (CCA) — Questions and Answers
Question 1: What is the primary purpose of the Jamf Pro Self Service application?
- To generate compliance reports for auditors
- To provide end users a portal to install approved apps, policies, and resources without IT intervention (Correct answer)
- To configure network settings on enrolled devices
- To allow administrators to remotely wipe managed devices
Correct answer: To provide end users a portal to install approved apps, policies, and resources without IT intervention
Self Service is a user-facing portal that empowers end users to install approved applications, run policies, and access resources without requiring direct IT assistance.
Question 2: In Jamf Pro (Casper Suite), which deployment method allows you to make an app available in Self Service without forcing installation?
- Push Install
- Silent Deploy
- Make Available in Self Service (Correct answer)
- Auto-Install
Correct answer: Make Available in Self Service
The 'Make Available in Self Service' deployment method lets end users choose when to install the app from the Self Service catalog.
Question 3: How are scripts deployed through Casper policies?
- Scripts are stored on the JSS and executed on target devices when policies run (Correct answer)
- They are compiled into apps first
- Users must manually download and run them
- Scripts are emailed to administrators
Correct answer: Scripts are stored on the JSS and executed on target devices when policies run
Scripts are uploaded to the JSS and executed on targeted devices when the associated policy runs, either on a schedule, at check-in, or on trigger events.
Question 4: What happens when a device is remotely wiped through Casper?
- All data and settings are erased, returning the device to factory defaults (Correct answer)
- Only email is deleted
- The device is temporarily disabled
- Only managed apps are removed
Correct answer: All data and settings are erased, returning the device to factory defaults
A remote wipe erases all data, settings, and user content from the device, returning it to factory defaults, typically used for lost or stolen devices.
Question 5: What is the key difference between 'Self Service' and 'Recurring Check-in' triggers in a Jamf Pro policy?
- There is no functional difference — both triggers run at the scheduled check-in time
- Self Service requires admin approval before running; Recurring Check-in does not require approval
- Self Service installs only apps; Recurring Check-in installs only scripts and packages
- Self Service runs policies immediately when users click them; Recurring Check-in runs policies automatically at each check-in interval (Correct answer)
Correct answer: Self Service runs policies immediately when users click them; Recurring Check-in runs policies automatically at each check-in interval
A Self Service trigger runs the policy on demand when a user initiates it from the app, while Recurring Check-in executes the policy automatically each time the device checks in with Jamf Pro.
Question 6: How does Jamf Pro's 'Local Accounts' policy payload help with user management?
- It creates, modifies, or deletes local user accounts on managed Macs (Correct answer)
- It syncs iCloud accounts to managed Macs
- It enables FileVault for user accounts
- It imports users from Active Directory
Correct answer: It creates, modifies, or deletes local user accounts on managed Macs
The Local Accounts policy payload in Jamf Pro lets admins create new local accounts, change passwords, reset home directories, or delete accounts on managed devices.
Question 7: Which Jamf Pro policy trigger would you use to deploy software immediately when a Mac checks in for the first time?
- Enrollment Complete (Correct answer)
- Login
- Startup
- Recurring Check-In
Correct answer: Enrollment Complete
The 'Enrollment Complete' trigger fires once right after a device successfully enrolls, making it ideal for initial software deployment.
Question 8: How can an administrator track which users have installed a specific item from Self Service?
- By querying the LDAP directory for installation events tied to user accounts
- By enabling verbose logging on the Self Service application via a configuration profile
- By checking the Self Service Analytics dashboard built into Jamf Pro
- By reviewing the Management History or Policy Logs for the device in Jamf Pro (Correct answer)
Correct answer: By reviewing the Management History or Policy Logs for the device in Jamf Pro
The Management History for a computer in Jamf Pro records all policy executions including those triggered via Self Service, showing which items were run and when.
Question 9: How does Casper handle software deployment to managed endpoints?
- Only through physical USB installation
- Through policies that can push packages, scripts, or App Store apps to targeted devices (Correct answer)
- By emailing installation files
- Users must download software manually
Correct answer: Through policies that can push packages, scripts, or App Store apps to targeted devices
Casper uses policies to deploy software packages, run scripts, or distribute App Store apps to targeted groups of devices automatically.
Question 10: What is the purpose of the 'Featured' section in Jamf Pro Self Service?
- To highlight selected apps and resources prominently at the top of the Self Service interface (Correct answer)
- To list only items scoped to administrators
- To show only recently added items from the past 7 days
- To display items that are mandatory and will auto-install
Correct answer: To highlight selected apps and resources prominently at the top of the Self Service interface
The Featured section displays selected apps and resources prominently, allowing administrators to draw attention to important or commonly used items.
Question 11: How does MDM (Mobile Device Management) enforce security on enrolled devices?
- Through configuration profiles that enforce passcode policies, encryption, and access restrictions (Correct answer)
- By physically locking devices
- By limiting battery usage
- By monitoring phone calls
Correct answer: Through configuration profiles that enforce passcode policies, encryption, and access restrictions
MDM enforces security through configuration profiles that set requirements for passcodes, encryption, app restrictions, and other security controls.
Question 12: What is the difference between managed and unmanaged apps in Casper?
- There is no practical difference
- Unmanaged apps perform better
- Managed apps are free; unmanaged are paid
- Managed apps can be remotely installed, updated, configured, and removed by IT; unmanaged apps cannot (Correct answer)
Correct answer: Managed apps can be remotely installed, updated, configured, and removed by IT; unmanaged apps cannot
Managed apps are under IT control through Casper — they can be remotely deployed, configured, updated, and removed, while unmanaged apps are user-installed and outside IT control.
Question 13: How can Jamf Pro help with compliance reporting?
- Via custom wallpapers
- Using smart groups to track compliance (Correct answer)
- Using user location data
- Through the Dock payload
Correct answer: Using smart groups to track compliance
Jamf Pro significantly aids compliance reporting through the use of smart groups. Administrators can create smart groups based on various criteria, such as devices with FileVault enabled, specific software installed, or particular security settings configured. These dynamic groups automatically update, providing real-time visibility into which devices meet compliance standards and which do not, simplifying auditing and reporting.
Question 14: What is DEP (Device Enrollment Program) in the context of Casper/Jamf?
- A device exchange plan
- A device recycling program
- An Apple program that automates device enrollment and initial configuration in Casper during setup (Correct answer)
- A data encryption protocol
Correct answer: An Apple program that automates device enrollment and initial configuration in Casper during setup
DEP (now Apple Business Manager) automates the enrollment of Apple devices into Casper/Jamf during initial device setup, enabling zero-touch deployment.
Question 15: What Jamf Pro inventory field stores the name of the user currently logged into a managed Mac, updated at each check-in?
- Assigned User
- Username (Last User) (Correct answer)
- LDAP User
- User and Location > Full Name
Correct answer: Username (Last User)
Jamf Pro records the username of the last logged-in user in inventory under the 'Username' field, which is updated each time the device checks in.
Question 16: Which Jamf Pro tool lets you test a package install interactively on a single device before wide deployment?
- Composer
- Recon
- Jamf Remote (Correct answer)
- Jamf Imaging
Correct answer: Jamf Remote
Jamf Remote allows administrators to push policies and packages to individual computers in real time for testing before broad rollout.
Question 17: In Jamf Pro, what is the purpose of assigning a 'User and Location' record to a managed computer?
- To associate the device with an owner for inventory, reporting, and user-targeted policy scoping (Correct answer)
- To enroll the user's iPhone alongside their Mac
- To set the device's hostname in DNS
- To configure the user's login password remotely
Correct answer: To associate the device with an owner for inventory, reporting, and user-targeted policy scoping
User and Location records link a managed device to a specific directory user, enabling user-targeted reporting, Self Service customization, and scope filtering.
Question 18: How does VPP (Volume Purchase Program) integration work with Casper?
- It manages phone plan volumes
- It provides volume discounts on hardware
- It enables organizations to purchase and distribute App Store apps to managed devices through Casper (Correct answer)
- It tracks data usage volumes
Correct answer: It enables organizations to purchase and distribute App Store apps to managed devices through Casper
VPP (now part of Apple Business Manager) allows organizations to purchase app licenses in volume and distribute them to devices through Casper without requiring Apple IDs.
Question 19: What role does the JSS (Jamf Software Server) play in endpoint management?
- It is a file storage server only
- It serves as the central management platform that communicates with and controls all enrolled devices (Correct answer)
- It handles only email services
- It is a backup server
Correct answer: It serves as the central management platform that communicates with and controls all enrolled devices
The JSS is the central hub of the Casper Suite, storing device information, managing policies, and communicating with enrolled devices.
Question 20: What is a configuration profile in Casper MDM?
- A hardware specification document
- A user biography page
- An XML payload that defines device settings, restrictions, and configurations applied to managed devices (Correct answer)
- A network topology diagram
Correct answer: An XML payload that defines device settings, restrictions, and configurations applied to managed devices
Configuration profiles are XML-based payloads that contain settings for Wi-Fi, email, VPN, restrictions, and other configurations pushed to managed devices.
Question 21: What Jamf Pro feature allows administrators to alert users about new or updated items available in Self Service?
- Smart Group change alerts delivered via configured webhook endpoints
- Self Service Notifications configured in the policy's Self Service payload (Correct answer)
- Email alerts triggered by the Jamf Pro notification engine rules
- Jamf Pro Push Notifications sent via APNs to device lock screen
Correct answer: Self Service Notifications configured in the policy's Self Service payload
The Self Service payload in a policy includes a notification option that sends a macOS notification to users, alerting them that an item is available in Self Service.
Question 22: Which file should you check first when a Jamf policy fails to install a package on a managed Mac?
- /var/log/system.log
- /Library/Logs/ManagedClient/
- /private/var/db/receipts/
- /var/log/jamf.log (Correct answer)
Correct answer: /var/log/jamf.log
The jamf.log file records all Jamf agent activity including policy execution, package download, and install errors, making it the primary troubleshooting log.
Question 23: How does the Casper Suite integrate with network infrastructure?
- Through LDAP integration, network segments, distribution points, and SCEP for certificate management (Correct answer)
- It only works on local networks
- It replaces network routers
- Network integration is not available
Correct answer: Through LDAP integration, network segments, distribution points, and SCEP for certificate management
Casper integrates with network infrastructure through LDAP directories, network segmentation for location-aware policies, distribution points, and certificate management.
Question 24: What role does inventory reporting play in license compliance?
- They track installed software against purchased licenses to identify compliance gaps (Correct answer)
- They manage software development licenses
- They only count physical devices
- Inventory reports have no relation to licensing
Correct answer: They track installed software against purchased licenses to identify compliance gaps
Inventory reports that track installed software across all devices enable comparison with purchased licenses to ensure the organization is properly licensed.
Question 25: Can eBooks (ePub files) be distributed to iOS devices through Jamf Pro Self Service?
- Yes, but only via configuration profiles, not directly through Self Service
- Yes, eBooks can be added to Jamf Pro and made available in the iOS Self Service app (Correct answer)
- No, eBooks require distribution exclusively through Apple School Manager
- No, Jamf Pro does not support eBook distribution to any device type
Correct answer: Yes, eBooks can be added to Jamf Pro and made available in the iOS Self Service app
Jamf Pro supports distributing eBooks (ePub files) to iOS devices, and they can be made available to users through the iOS Self Service application.
Question 26: What file format does Jamf Pro use to package and deploy macOS applications via policy?
- .pkg (Correct answer)
- .app
- .zip
- .dmg
Correct answer: .pkg
Jamf Pro deploys applications using .pkg (package) files, which macOS Installer can process silently without user interaction.
Question 27: What macOS mechanism does Jamf Pro use to enforce that only approved software can be launched by standard users?
- Parental Controls
- System Integrity Protection
- FileVault encryption
- Gatekeeper + allowed/blocked process policy payloads (Correct answer)
Correct answer: Gatekeeper + allowed/blocked process policy payloads
Jamf Pro can configure Gatekeeper settings via configuration profiles and use allowed/blocked process payloads in policies to restrict which apps standard users can run.
Question 28: What network ports must be open for Casper/Jamf communication?
- Port 22 only
- All ports must be open
- Ports 443 (HTTPS), 8443 (JSS), and 2195/2196 (APNs) among others depending on configuration (Correct answer)
- Only port 80
Correct answer: Ports 443 (HTTPS), 8443 (JSS), and 2195/2196 (APNs) among others depending on configuration
Key ports include 443 for HTTPS communication, 8443 for JSS management, and Apple Push Notification ports for MDM commands, with additional ports depending on services used.
Question 29: What is the function of the Jamf Pro Patch Management feature?
- It allows remote screen viewing
- It monitors CPU usage
- It updates Apple IDs
- It tracks and deploys software updates (Correct answer)
Correct answer: It tracks and deploys software updates
Jamf Pro's Patch Management automates the process of identifying, testing, and deploying software updates for third-party applications and macOS. This ensures that all managed devices have the latest security patches and feature enhancements. By keeping software up-to-date, organizations can reduce vulnerabilities and maintain a secure and efficient computing environment.
Question 30: Which Jamf Pro policy payload type would you use to run a shell script after a package installs successfully?
- Extension Attribute
- Scripts payload with After run order (Correct answer)
- Configuration Profile payload
- Files & Processes payload
Correct answer: Scripts payload with After run order
The Scripts payload in a Jamf policy lets you specify shell scripts to run Before or After the package installation payload completes.
Question 31: In Jamf Pro, which feature allows you to bind a Mac to Active Directory so users can log in with their AD credentials?
- Keychain sync
- Local account creation script
- LDAP server configuration only
- Directory Binding via a Configuration Profile or policy (Correct answer)
Correct answer: Directory Binding via a Configuration Profile or policy
Jamf Pro can bind Macs to Active Directory using a Directory Binding payload in a Configuration Profile or via a policy, enabling AD login.
Jamf Certified Casper Administrator (CCA)
The Jamf Certified Casper Administrator (CCA) certification validates advanced Apple device management skills using the Jamf Pro (formerly Casper Suite), covering software distribution, mobile device management, self-service configuration, user management, and scripting for enterprise environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds