CCA User Management and Privileges Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCA User Management and Privileges flashcards as text
Which Jamf Pro configuration profile payload controls what users see on the macOS login window, such as hiding the 'Other' user option?
Answer: Login Window payload
The Login Window payload in a macOS configuration profile controls login window display options including hiding/showing user lists and the 'Other' option.
In Jamf Pro, how do you prevent a standard user from installing applications from the internet on a managed Mac?
Answer: Use a Restrictions profile to set Gatekeeper to 'Mac App Store only'
Setting the Gatekeeper policy via a Restrictions configuration profile to 'Mac App Store' prevents users from installing unsigned or internet-sourced applications.
What Jamf Pro feature can be used to automatically assign a newly enrolled Mac to the correct user by looking them up in a connected LDAP directory?
Answer: User Assignment during enrollment via LDAP lookup
Jamf Pro can prompt for or auto-populate user assignment during enrollment by querying the connected LDAP directory, linking the device to its owner immediately.
Which Jamf Pro policy option would you use to run a script as the currently logged-in user rather than as root?
Answer: Set the script's run-as option to 'Current User' in the Scripts payload
In a Jamf Pro policy's Scripts payload, setting the script to run as 'Current User' executes it in the user's session context rather than as root.
What is the Jamf Pro recommended method to securely recover a FileVault-encrypted Mac if the user forgets their password?
Answer: Use the FileVault Recovery Key escrowed to Jamf Pro to unlock the disk
Jamf Pro can escrow FileVault Personal Recovery Keys (PRK) to the Jamf Pro database, allowing admins to retrieve the key and unlock an encrypted Mac when needed.
In Jamf Pro, which scope type would target a policy to all managed Macs where a specific LDAP user group member is currently logged in?
Answer: Scope the policy to an LDAP User Group
Scoping a Jamf Pro policy to an LDAP User Group targets it to devices where a member of that directory group is logged in, enabling user-based policy delivery.