alisheikhpour wrote:
I could be off here, but my initial thought was the school was doing this because our exams are administered on our own computers using “Examplify”.
I'm so glad I'm done with that. I would hate to be in higher education today.
Just so you know, you're playing with fire there. Early in the term, try to ensure that the officially blessed version of Examplify works with your Mac. Then, do not update your computer in any way or for any reason. Otherwise, you will get burned.
Apparently Exemplify has an iPad version. See if you can use that. The same rules apply, but the iPad version may be more stable - especially if you are being forced to use AV on your Mac. In any case, can't hurt to have a backup.
So if someone attempts to modify the software internally or whatnot, most of these AVs might flag the software as PUA?
These AVs will regularly flag system files as malicious. The better ones will detect about half of actual malware. Unfortunately, they rarely tell users what the actual files were. Instead, they only report their scary-sounding code names.
Alternatively, they’re trying to protect their own systems?
I'm sure that their own system has very poor security. No target is softer than higher ed IT. It's just a way to control people, that's all. They really don't like Mac users. They will push you to install AV and to install every latest update from Apple, but then they will require out-of-date versions of software like Examplify. When you can't do the exam or complete your coursework, it will be your problem. They'll blame you. They'll blame Apple. They are not your friends.
I don’t know but I sort of doubt the IT department is so selflessly trying to protect me from myself. The AV they’re pushing hardest is SentinelOne, but I’ve seen the logs IT admins can get from users using SentinelOne and it’s literally Big Brother on steroids.
While they definitely want to control you, they will not able to surveil all students' log files. I assume that if they require this software, they should have some way of ensuring compliance. You probably don't have to worry about personal data.
Here are the most popular AV products from EtreCheck reports:

SentinelOne, and any of the others, were all under 1%. Because SentinelOne has so few data points, I can't reliably judge its performance in detecting malware like I can the more popular products. Let's hope that with more SentinelOne data, it would show significantly better performance 😄.
However, I did find a few EtreCheck reports with SentinelOne installed:
FCPX 10.6.5 constantly crashes on MacOS 1… - Apple Community
late 2015 27" iMac keeps slowing down; sp… - Apple Community
https://discussions.apple.com/thread/254619275
https://discussions.apple.com/thread/254785658
So it looks like it has one network System Extension that is typically not running. As far as launchs tasks go, it's relatively high with 8 separate tasks. Because SentinelOne has so few installations, it's hard to judge how problematic it might be.
Generally speaking, if someone has power over you, it's best to keep them happy. If SentinelOne will make them happy, it should be fine.