Court-owned MacBooks must escrow FileVault recovery material and remain under supervised management. Which approach meets that requirement?
Select an answer to reveal the explanation.
Short Explanation
FileVault escrow is an MDM job, like the courthouse lockbox that holds spare keys—only Workspace ONE UEM enrollment can take that deposit. A Carbon Black sensor group watches processes; it does not become the Mac’s MDM or hold FileVault recovery. NSX tags live on datacenter VMs, not on courtroom laptops.
Full Explanation
Supervised macOS management, FileVault personal recovery-key escrow, and bootstrap-token workflows require Workspace ONE UEM MDM enrollment. Carbon Black Cloud sensor groups apply prevention policy; they do not replace MDM or escrow disk-encryption keys. NSX-T identity firewall and security tags do not manage Mac hardware encryption. Local-admin plus sensor is not a supported FileVault escrow path.