Skip to content

DEP-2026 Apple Deployment and Management Practice Questions

Prepare for DEP-2026 with more than an answer.

135 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$149 USD
Time limit
120 minutes
Questions on the exam
~80
Passing score
75%
Level
Intermediate
Valid for
2 years
Domains covered on the exam 13
  1. Plan a Deployment7%
  2. Prepare Your Environment8%
  3. Device Enrollment12%
  4. Apple Business Manager and Apple School Manager12%
  5. Apple Configurator4%
  6. Device Setup6%
  7. Device Configuration3%
  8. Identity Services5%
  9. Managing Content and Data Flow7%
  10. Device Security15%
  11. Network Integration8%
  12. Software Updates8%
  13. Device Support5%
  1. 1

    A healthcare provider is deploying Shared iPads for nursing staff. Multiple nurses will use the same physical iPad during different shifts. Which of the following is a strict requirement for implementing Shared iPad in this environment?

    Show answer details

    Correct answer: A

    Shared iPad is an exclusive feature for organization-owned devices. It requires the devices to be supervised and enrolled via Automated Device Enrollment (ADE) through Apple Business Manager or Apple School Manager. Users then log in using Managed Apple Accounts.

    flowchart LR A[ABM / ASM] -->|ADE Token| B[MDM Server] B -->|Shared iPad Profile| C[iPad] D[Nurse A] -->|Managed Apple Account| C E[Nurse B] -->|Managed Apple Account| C
  2. 2

    A school district recently utilized the new MDM service migration feature introduced in macOS Tahoe and iOS 26 to move devices to a new management platform. To ensure compliance, they configured an enrollment deadline. What happens on a macOS Tahoe device if the user ignores all prompts and the enrollment deadline is reached?

    Show answer details

    Correct answer: C

    With the new MDM service migration feature in macOS Tahoe, administrators can enforce an enrollment deadline. Once this deadline is reached, the device displays a persistent, full-screen Setup Assistant interface requiring the user to complete the enrollment process into the new MDM service before they can resume using the device.

  3. 3

    True or False: When manually adding an iPhone to Apple Business Manager using Apple Configurator, the user has a 30-day provisional period during which they can release the device from management and remove it from ABM.

    Show answer details

    Correct answer: A

    True. As a security and privacy measure, any device manually added to Apple Business Manager or Apple School Manager via Apple Configurator enters a 30-day provisional period. During this time, the end user can choose to leave remote management from the device settings, which completely removes the device from ABM/ASM.

  4. 4

    A systems administrator is designing a deployment strategy for a fleet of corporate-owned macOS Tahoe devices. They need to understand the underlying communication architecture that allows the MDM server to prompt devices to check in for new configurations. Which Apple service is primarily responsible for waking up the managed devices and instructing them to contact the MDM server?

    Show answer details

    Correct answer: A

    The Apple Push Notification service (APNs) is the core component of the Apple MDM framework that maintains a persistent connection with devices. It securely wakes up devices and alerts them to contact their configured MDM server for pending commands or profile updates.

  5. 5

    When planning a macOS Tahoe deployment that enforces FileVault encryption, an architect needs to ensure that mobile device management (MDM) can escrow the recovery key securely. Which TWO components are critical for automatically granting volume ownership and allowing automatic FileVault recovery key rotation via MDM? (Select TWO)

    Show answer details

    Correct answer: B, D

    The bootstrap token is escrowed to the MDM server and is used to automatically grant a secure token to mobile accounts and local users logging in for the first time. In macOS Tahoe, it is also required to automatically rotate an existing FileVault recovery key prior to escrow.

    A secure token is a cryptographic attribute granted to user accounts that allows them to unlock the FileVault-encrypted volume. The interaction between the bootstrap token and secure token establishes volume ownership.

  6. 6

    A multinational financial corporation is rolling out a new BYOD (Bring Your Own Device) program for its contractors. The security team insists on strict separation of corporate and personal data, but also requests the ability to remotely wipe the entire device if the contractor is terminated.

    As the lead Apple deployment architect, you review the MDM capabilities for user-owned devices under the User Enrollment model.

    Based on Apple's ownership models and MDM framework, how should you address the security team's request regarding the remote wipe capability?

    flowchart TD A[Device Enrollment Type] --> B{Ownership Model} B -->|User-Owned| C[User Enrollment] B -->|Organization-Owned| D[Device Enrollment / ADE] C --> E[Managed Corporate Data Container] C --> F[Personal Data Container] D --> G[Full Device Management]
    Show answer details

    Correct answer: C

    Under Apple's User Enrollment model for user-owned devices, privacy is paramount. The MDM server is strictly prevented from issuing commands that affect personal data, such as a full device wipe (DeviceErase), clearing the device passcode, or viewing personal app inventory. The MDM can only remove the Managed Apple Account and the associated corporate data container.

Create an account to continue.