Apple DEP - 2024 Flashcards

Need More Study

1
Q

Relays

A

An array of dictionaries that describes one or more relay servers that can be chained together.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RelayUUID

A

A globally-unique identifier for this relay configuration. This UUID is used to route Managed Apps through the servers contained in Relays.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Match domains

A

A list of domain strings used to determine which connection should be routed through the servers contained in Relays. Any connection that matches the domain exactly or that is a subdomain of the listed domain will use the relay servers, unless they match an excluded domain. If no domains are listed, traffic to all domains, except those matching an excluded domain, is routed to the relay servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Excluded domains

A

A list of domain strings that shouldn’t be routed through the servers contained in Relays. Any connection that matches the domain exactly or that is a subdomain of the listed domain will not use the relay server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

APNS

A

TCP port 5223, 443, 2197 and IP range - 17.0.0.0/8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Declarative Device Management

A

It uses declarations to asynchronously update the device settings, restrictions, assets, and more. With status channels, devices proactively report the status of objects like passcode compliance and MDM-installed apps — without constant polling from the MDM server.

With declarative device management, the device asynchronously applies settings and reports the status back to the MDM solution without constant polling.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

macOS Recovery on a Mac with Apple silicon Available Apps

A

Time Machine System Restore
Install macOS
Safari
Disk Utility
Startup Security Utility
Terminal
Share Disk
Startup Disk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Organization ID - Apple Business manager

A

Your Organization ID can be used to associate reseller-purchased devices or custom apps from third-party developers with Apple Business Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Federated Authentication - Apple Business manager

A

Federated authentication allows your users to sign in to their Managed Apple ID by signing into their Identity Provider
Google Workspace
Microsoft Entra ID
using their own Identity Provider

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

MDM Server Assignment -Apple Business manager

A

MDM server token download to upload to MDM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

declarative device management

A

a device can apply management logic to itself without cues from the server and report important state changes to the server as they happen. The server doesn’t need to cue or poll the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Automated Device Enrollment

A

provides a zero-touch process with the most automated and scalable approach to procure, distribute, enroll, and manage organization-owned devices with MDM. Devices must be in your Apple Business Manager or Apple School Manager portal, and devices your organization purchases directly from Apple or a participating Apple Authorized Reseller or carrier are automatically added. You can add other organization-owned devices to the portal manually. Never add user-owned devices to your Apple Business Manager or Apple School Manager portal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Device Enrollment

A

covers organization-owned devices that aren’t eligible for Automated Device Enrollment. Organizations use Device Enrollment to manually enroll devices in their MDM solutions. Examples include donated devices, devices set up by the user that are already in use, and devices bought outside official Apple procurement channels. Anyone with access to your MDM solution’s enrollment portal can enroll or reenroll devices already deployed. Unlike Automated Device Enrollment, a user can remove management from the device after enrollment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

User Enrollment

A

is for user-owned devices and requires an organization-provided Managed Apple ID. To enroll their devices in MDM, users either use their Managed Apple ID or manually install a user enrollment profile. If a user removes the enrollment profile, the MDM configuration profiles, settings, and managed apps are removed with it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Apple Configurator on a Mac

A

to add iPhone, iPad, and Apple TV devices to your Apple Business Manager or Apple School Manager account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Apple Configurator app for iPhone

A

to add a Mac, iPhone, or iPad

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

user-owned device

A

You can’t manage Find My, Activation Lock, or Managed Lost Mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Account-Based User Enrollment

A

users sign in to their work or school account on their device using their Managed Apple ID. If the account is federated, the user is redirected to the federated identity provider. Service discovery identifies the MDM solution’s enrollment URL. The MDM solution sends an enrollment profile to the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Profile-Based User Enrollment

A

the organization provides users with a URL or a self-service app and users then take the following steps:

Open the self-service app or open the URL in a browser. The device downloads the enrollment profile and any configuration profiles.

Agree to install the downloaded configuration profiles and enroll in MDM. This process on the Mac differs from the process on iPhone and iPad.

Sign in with their Managed Apple ID. If the account is federated, users are redirected to the federated identity provider.

When enrollment completes, users have an additional account in Settings on their iPhone, iPad, or Mac.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

apple silicon how to block users from recovery mode

A

You can set Recovery Lock for computers with Apple silicon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

DNS

A

An MDM solution must use a fully qualified domain name that can be resolved from both inside and outside the organization’s network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

IP address

A

Most MDM solutions require a static IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Apple devices use a wide range of 802.1X wireless authentication protocols

A

Apple devices into many Remote Authentication Dial-In User Service (RADIUS) authentication environments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

authenticate wireless devices to your network using one of these strategies:

A

Open networks/Public
Captive networks
Wi-Fi Protected Access 2 (WPA2) Personal
Wi-Fi Protected Access 3 (WPA3) Personal
WPA2 Enterprise
WPA3 Enterprise

Configuration method (iOS 16.4, iPadOS 16.4, and macOS Ventura 13.3 or later): Private networks configured using a mobile device management (MDM) profile are preferred over manually joined networks.

Highest supported Wi-Fi standard: For example, Wi-Fi 6 networks are preferred over Wi-Fi 5 networks.

Frequency band: 6 GHz, then 5 GHz, then 5 GHz (DFS), then 2.4 GHz.

Security: WPA Enterprise, then WPA Personal, then WEP.

Signal strength: Learn more about RSSI and wireless roaming for enterprise.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

standard VPN protocols

A

IKEv2, Cisco IPsec, and L2TP over IPsec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Bonjour zero-configuration network protocol

A

With Bonjour, devices can automatically find services on a network
iPhone, iPad, and Mac can use Bonjour to connect to AirPrint-compatible printers and to AirPlay-compatible devices like Apple TV. Some apps and built-in iOS, iPadOS, and macOS features also use Bonjour to discover other devices for collaboration and sharing. However, you can configure both AirPrint and AirPlay to be fully functional in an organization without the use of Bonjour. For example, you can manage AirPrint destinations using DNS records within an organization, whereas AirPlay uses a direct peer-to-peer connectivity model by default.

27
Q

Platform SSO

A

With macOS 13 or later, SSO extensions are available to the login window. Users can unlock their Mac computer with their identity provider (IdP) credentials, then automatically sign in to apps and websites. The local account password and the IdP password are kept in sync, and users can continue to unlock their Mac computers with Touch ID and Apple Watch.

28
Q

Mac computers using macOS 13 or later also limit the profiles command-line tool to 10 of the following requests per 24 hours for devices owned by an organization that appear in Apple School Manager, Apple Business Manager, or Apple Business Essentials:

A

profiles show

profiles validate

profiles renew

29
Q

How Apple separates user data from organization data

A

App data containers
Calendar
Keychain items
Mail attachments and body of the mail message
Notes
Reminders
icloud

30
Q

MDM solution to convert unmanaged apps to managed apps

A

If the device is supervised, the switch to a managed app from an unmanaged app happens without user interaction
If the MDM solution requests it. If the device isn’t supervised, the user must formally accept management.

31
Q

Managed Open In restrictions (iOS and iPadOS)

A

Allow documents from unmanaged sources in managed destinations
Allow documents from managed sources in unmanaged destinations
Managed pasteboard
Mark apps as nonremovable
Prevent Managed Apps from backing up data
Use app configuration settings
Use app feedback settings that can be read by MDM
Download managed documents from Safari
Prevent Managed Apps from storing data in iCloud

32
Q

A Managed Apple ID

A

Using account-driven Device Enrollment to enroll iPhone and iPad devices and Mac computers in management without a user needing to manually install a profile
Configuring access management to control where Managed Apple IDs can sign in and what apps and services they can use

33
Q

Your passcode policies can include these requirements on iPhone, iPad, and Mac

A

An alphanumeric value

Minimum passcode length

Minimum number of complex characters

Maximum passcode age

Time before autolock

Passcode history (unable to use previous passwords)

Grace period for device lock

Maximum number of failed attempts before a device is erased

34
Q

Touch ID doesn’t replace the need for a device passcode or user password

A

which is still required after device startup, restart, or logout (on a Mac)
However, a device passcode or user password is always required in some scenarios (for example, to change an existing device passcode or user password or to remove existing fingerprint enrollments or create new ones)

35
Q

The four stages of User Enrollment into MDM are

A

Service discovery: The device identifies itself to the MDM solution.

User enrollment: The user provides credentials to an identity provider (IdP) for authorization to enroll in the MDM solution.

Session token: A session token is issued to the device to allow ongoing authentication.

MDM enrollment: The enrollment profile is sent to the device with payloads configured by the MDM administrator.

36
Q

Apple School manager

A

Are integrated with a Student Information System (SIS) or uploading .csv files (Apple School Manager only) SFTP

37
Q

An MDM solution can identify the following for User Enrollment

A

Device name

Serial number

Model name and number

Capacity and space available

Operating system version number

Installed apps

38
Q

An MDM solution can’t identify the following for User Enrollment

A

Email, calendars, and contacts

SMS or iMessage

Safari browser history

FaceTime or phone call logs

Personal reminders and notes

Frequency of app use

Device location

39
Q

Apple bypass code generator

A

The MDM solution creates its own bypass code, and sends it to Apple servers

40
Q

Apple Customer Number

A

The Apple Customer Number is the account number (or numbers) assigned to your organization by Apple, used to purchase Apple hardware or software. It’s required in order to verify your organization’s eligibility for certain programs. If you don’t know the numbers, contact your purchasing agent, finance department, or Apple account team. This number isn’t the same as your GSX account number.

Note: When entering your Apple Customer Number, omit any leading zeros.

41
Q

Reseller Number

A

A Reseller Number is a unique identifier for each Apple Authorized Reseller or cellular carrier who participates in Apple School Manager. When you add a participating Apple Authorized Reseller’s or carrier’s Reseller Number to your account profile (and you give that reseller your Organization ID), you authorize that reseller to submit devices you purchased through them to Apple so their serial numbers appear in Apple School Manager.

42
Q

Organization ID

A

An Organization ID is your unique identifier in Apple School Manager. When you give a participating Apple Authorized Reseller or cellular carrier your Organization ID (and you add that reseller’s Number to your account profile), you authorize that reseller to submit devices you purchased through them to Apple so their serial numbers appear in Apple School Manager. The Organization ID can also be used with app developers so they can distribute Custom Apps specific to your organization.

43
Q

Apple School Manager

A

Sync user accounts from your Student Information System(SIS), Google Workspace, Microsoft Entra ID, or your identity provider, or with files you create and upload using SFTP.

44
Q

Apple Business Manager Non Federated Accounts

A

Users with the role of Administrator or People Manager can’t sign in using federated authentication; they can only manage the federation process.

45
Q

Apple Business Manager Server Setup

A

Download the public key certificate file from your MDM solution.
Saving a public certificate to Apple Business Manager generates a server token you upload into your MDM Solution

46
Q

Manual Added device into ABM 30 day counter

A

This 30-day provisional period begins after you assign the device to and enroll it in a third-party MDM server linked to Apple Business Manager, Apple Business Essentials, or Apple School Manager.

47
Q

Apple School Manager Roles

A

Administrator
Site Manager
People Manager
Device Enrollment Manager
Content Manager
Manager
Staff
Instructor
Student

48
Q

Apple Business Manager Roles

A

Administrator
People Manager
Device Enrollment Manager
Content Manager
Staff

49
Q

tethered caching.

A

Data is stored on the mac device

50
Q

New apple devices into ABM

A

You must enter your Apple Customer Numbers or the Reseller Numbers of your participating Apple Authorized Reseller or carrier

51
Q

Auto Advance for Mac or Apple TV

A

Auto Advance allows you to skip all Mac or Apple TV Setup Assistant panes automatically.

52
Q

What is Classroom

A

App for teachers - When teaching in class, you can launch a specific app, website, or textbook page. You can also send documents to and receive them from your students, and share student work locally on a TV, monitor, or projector using Apple TV. Finally, you can see which apps students are working in and, at the end of the class, view a summary of how students spent their time

53
Q

Use of cameras is restricted

A

Cameras are disabled and the Camera icon is removed from the Home Screen in iOS and iPadOS. Users can’t take photographs or videos.

54
Q

Install apps using App Store restricted

A

App Store is disabled and its icon is removed from the Home Screen. Users can’t install or update apps.

55
Q

four types of MDM queries

A

1 device information
2 operating system
3 installed app
4 security

56
Q

Network test

A

Network Quality- Tests upload and download speeds

Netstat - generates displays that show network status and protocol statistics

57
Q

Always on VPN

A

protocol IKEv2

58
Q

Rapid Security Responses and MDM

A

MDM solutions can use the following restriction keys on supervised iPhone, iPad and Mac devices:

allowRapidSecurityResponseInstallation: To disable the responses from being applied.

allowRapidSecurityResponseRemoval: To block the user from being able to remove the responses.

59
Q

Lockdown Mode

A

Configuration profiles can’t be installed, and the device can’t be enrolled in Mobile Device Management or device supervision while in Lockdown Mode.

60
Q

Enrollment type

A
61
Q

types enforce supervision on Mac computers running macOS 11 or later?

A

Automated Device Enrollment
Device Enrollment

62
Q

Your organization has 50 Apple devices deployed over three network subnets.
You want to turn on content caching on a Mac mini to optimize your internet bandwidth for all three network subnets.
Which setting should you use in the content caching advanced options?

A

Cache content for: devices using the same public IP address
Use custom public IP addresses
Devices using custom local networks

63
Q

App notifications

A

disable HTTPS Interception
entire 17.0.0.0/8 address block

64
Q

MacOS Recovery

A

Need to enter Admin password before getting to the recovery options