System Integrity Protection (SIP) restricts root user actions, protecting critical system files and processes from modification, even with admin privileges. Enabled by default since macOS Sierra.
Option A: XProtect scans for malware, not limits root.
Option B: Full Disk Access grants permissions, not restricts.
Option D: Secure Enclave handles encryption, not root limits.
[References: Apple Support - "About System Integrity Protection" (support.apple.com/HT204899)., , , ]
Submit