Challenge accepted. And it's not a huge challenge. I'd say not even a mild one.
they usually work in kernel extensions or use https://developer.apple.com/documentation/endpointsecurity - which gives them pretty good coverage of all the processes running, and arguments etc
They have no clue what legal requirements are imposed on the company that led to those restrictions. They could easily land themselves or the entire business in hot water by not complying. It doesn't matter how easy the controls are to bypass. Like, it's easy to pick or cut a LOTO lock, but that doesn't mean it's fine to do that.
So while corporate restrictions sometime (but only sometime!) make sense, the configuration where a terminal is allowed while a browser is not - don't.