Deck 7: Macintosh and Linux Boot Processes and File Systems

Full screen (f)
exit full mode
Question
What file is used to store any file information that is not in the MDB or a VCB?​

A)​page file
B)​metadata database file
C)slack file
D)extents overflow file
Use Space or
up arrow
down arrow
to flip the card.
Question
Adding the _____________ flag to the ​ls -l command has the effect of of showing all files beginning with the "." character in addition to other files.

A)-s​
B)​-d
C)-l
D)-a
Question
If a file has 510 bytes of data, what is byte 510?​

A)​The physical EOF.
B)​The logical EOF.
C)The terminating EOF.
D)The end of the sector.
Question
​What command below will create a symbolic link to a file?

A)​ln -s
B)​ls -ia
C)ln -l
D)ls -h
Question
Capitalization, or lack thereof, makes no difference with UNIX and Linux commands.​
Question
Select below the command that can be used to display bad block information on a Linux file system, but also has the capability to destroy valuable information.​

A)​dd
B)​fdisk
C)badblocks
D)mke2fs
Question
The Mac OS reduces file fragmentation by using _______________.

A)​inodes
B)​superblocks
C)clumps
D)chunks
Question
Who is the current maintainer of the Linux kernel?​

A)​Tim Cook
B)​Eric Shmidt
C)Linus Torvalds
D)Lennart Poettering
Question
The term "kernel" is often used when discussing Linux because technically, Linus is only the core of the OS.​
Question
What type of block does a UNIX​/ Linux computer only have one of?​

A)​boot block
B)​data block
C)inode block
D)superblock
Question
In a B*-tree file system, what node stores link information to previous and next nodes?​

A)​inode
B)​header node
C)index node
D)map node
Question
Linux is a certified UNIX operating system.​
Question
The ______________ command can be used to see network interfaces.​

A)​ifconfig
B)​ipconfig
C)show interfaces
D)show ip brief
Question
________________ is a specialized carving tool that can read many image file formats, such as RAW and Expert Witness.​

A)​AccessData FTK
B)​X-Ways Forensics
C)Guidance Software EnCase
D)Foremost
Question
What file under the ​/ etc folder contains the hashed passwords for a local system?​

A)​passwd
B)​hashes
C)shadow
D)users
Question
​On Mac OS X systems, what utility can be used to encrypt ​/ decrypt a user's home directory?

A)​Disk Utility
B)​BitLocker
C)FileVault
D)iCrypt
Question
The only pieces of metadata not in an inode are the filename and path.​
Question
In UNIX and Linux, everything except monitors are considered files.​
Question
What is the minimum size of a block in UNIX​/ Linux filesystems?​

A)​128 bytes
B)​512 bytes
C)1024 bits
D)2048 bits
Question
As part of a forensics investigation, you need to recover the logon and logoff history information on a Linux based OS. Where can this information be found?​

A)​​/ var​/ log​/ utmp
B)​​/ var​/ log​/ wtmp
C)​/ var​/ log​/ userlog
D)​/ var​/ log​/ system.log
Question
Match each term with its definition:

-?A node that stores information about B*-tree file.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Match each term with its definition:

-?A key part of the Linux file system, these informatuin nodes contain descriptive file or directory data, such as UIDS, GIDs, modification times, access times, creation times, and file locations.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Since Mac OS 8.6, _______________ have been available for use in managing passwords for applications, web sites, and other system files.​
Question
A hash that begins with "$6" in the shadow file indicates that it is a hash from what hashing algorithm? ​

A)​MD5
B)​Blowfish
C)SHA-1
D)SHA-512
Question
Linux supports a wide range of file systems. Distinguish the three Extended File Systems of Linux.​
Question
What information below is not included within an inode??

A)?The mode and type of the file or directory
B)?The number of links to a file or directory
C)The file's or directory's last access time and last modified time
D)The file's or directory's path

Question
Match each term with its definition:

-?A block in the Linux file system that specifies and keep tracks of the disk geometry and available space and manages the file system.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Within the ​/ etc​/ shadow file, what field contains the password hash for a user account if one exists?​

A)​1st field
B)​2nd field
C)3rd field
D)4th field
Question
Match each term with its definition:

-The part of a Mac file containing file metadata and application information, such as menus, dialog boxes, icons, executable code, and controls. Also contains resource map and header information, window locations, and icons. ?

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
What are bad blocks, and how do you find them?​
Question
An assigned inode has _____ pointers that link to data blocks and other pointers where files are stored.​
Question
Match each term with its definition:

-?A Mac file that organizes the directory hierarchy and file block mapping for File Manager.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Match each term with its definition:

-An area of the Mac file system containing information from the Master Directory Block.?

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Match each term with its definition:

-?The part of a Mac file containing the file's actual data, both user-created data and data written by applications, as well as a resouce map and header information, window locations, and icons.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
​________________ contain file and directory metadata and provide a mechanism for linking data stored in data blocks.

A)​Blocks
B)​Clusters
C)Inodes
D)Plist files
Question
________ links are simply pointers to other files and aren't included in the link count.​
Question
Where is the root user's home directory located on a Mac OS X file system?​

A)​​/ root
B)​​/ private​/ var​/ root
C)​/ private​/ spool​/ root
D)​/ home​/ root
Question
Match each term with its definition:

-?In the Mac file system, a group of consecutive logical blocks assembled in a volume when a file is saved.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Match each term with its definition:

-??A block in the Linux file system where directories and files are stored on a drive.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Match each term with its definition:

-In the Mac file system, a collection of data that can't exceed 512 bytes. Assembled in allocation blocks to store files in a volume.?

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Question
Explain why one should have Apple factory training before attempting an acquisition on a Mac computer.​
Question
​What is a plist file?
Question
​Compare and contrast the data fork and resource fork of a Mac file.
Question
As you've learned, Linux commands use options to create variations of a command. Describe ​the rules for grouping letter arguments.
Question
Explain the differences between a hard link and a symbolic link.​
Question
After making an acquisition on a Mac computer, the next step is examining the image of the file system with a forensics tool. ​Explain how to select the proper forensics tool for the task.
Question
Describe a tarball.​
Question
UNIX and Linux ​have four components defining the file system. Identify and give a brief description of each.
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/48
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 7: Macintosh and Linux Boot Processes and File Systems
1
What file is used to store any file information that is not in the MDB or a VCB?​

A)​page file
B)​metadata database file
C)slack file
D)extents overflow file
D
2
Adding the _____________ flag to the ​ls -l command has the effect of of showing all files beginning with the "." character in addition to other files.

A)-s​
B)​-d
C)-l
D)-a
D
3
If a file has 510 bytes of data, what is byte 510?​

A)​The physical EOF.
B)​The logical EOF.
C)The terminating EOF.
D)The end of the sector.
B
4
​What command below will create a symbolic link to a file?

A)​ln -s
B)​ls -ia
C)ln -l
D)ls -h
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
5
Capitalization, or lack thereof, makes no difference with UNIX and Linux commands.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
6
Select below the command that can be used to display bad block information on a Linux file system, but also has the capability to destroy valuable information.​

A)​dd
B)​fdisk
C)badblocks
D)mke2fs
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
7
The Mac OS reduces file fragmentation by using _______________.

A)​inodes
B)​superblocks
C)clumps
D)chunks
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
8
Who is the current maintainer of the Linux kernel?​

A)​Tim Cook
B)​Eric Shmidt
C)Linus Torvalds
D)Lennart Poettering
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
9
The term "kernel" is often used when discussing Linux because technically, Linus is only the core of the OS.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
10
What type of block does a UNIX​/ Linux computer only have one of?​

A)​boot block
B)​data block
C)inode block
D)superblock
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
11
In a B*-tree file system, what node stores link information to previous and next nodes?​

A)​inode
B)​header node
C)index node
D)map node
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
12
Linux is a certified UNIX operating system.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
13
The ______________ command can be used to see network interfaces.​

A)​ifconfig
B)​ipconfig
C)show interfaces
D)show ip brief
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
14
________________ is a specialized carving tool that can read many image file formats, such as RAW and Expert Witness.​

A)​AccessData FTK
B)​X-Ways Forensics
C)Guidance Software EnCase
D)Foremost
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
15
What file under the ​/ etc folder contains the hashed passwords for a local system?​

A)​passwd
B)​hashes
C)shadow
D)users
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
16
​On Mac OS X systems, what utility can be used to encrypt ​/ decrypt a user's home directory?

A)​Disk Utility
B)​BitLocker
C)FileVault
D)iCrypt
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
17
The only pieces of metadata not in an inode are the filename and path.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
18
In UNIX and Linux, everything except monitors are considered files.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
19
What is the minimum size of a block in UNIX​/ Linux filesystems?​

A)​128 bytes
B)​512 bytes
C)1024 bits
D)2048 bits
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
20
As part of a forensics investigation, you need to recover the logon and logoff history information on a Linux based OS. Where can this information be found?​

A)​​/ var​/ log​/ utmp
B)​​/ var​/ log​/ wtmp
C)​/ var​/ log​/ userlog
D)​/ var​/ log​/ system.log
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
21
Match each term with its definition:

-?A node that stores information about B*-tree file.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
22
Match each term with its definition:

-?A key part of the Linux file system, these informatuin nodes contain descriptive file or directory data, such as UIDS, GIDs, modification times, access times, creation times, and file locations.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
23
Since Mac OS 8.6, _______________ have been available for use in managing passwords for applications, web sites, and other system files.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
24
A hash that begins with "$6" in the shadow file indicates that it is a hash from what hashing algorithm? ​

A)​MD5
B)​Blowfish
C)SHA-1
D)SHA-512
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
25
Linux supports a wide range of file systems. Distinguish the three Extended File Systems of Linux.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
26
What information below is not included within an inode??

A)?The mode and type of the file or directory
B)?The number of links to a file or directory
C)The file's or directory's last access time and last modified time
D)The file's or directory's path

Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
27
Match each term with its definition:

-?A block in the Linux file system that specifies and keep tracks of the disk geometry and available space and manages the file system.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
28
Within the ​/ etc​/ shadow file, what field contains the password hash for a user account if one exists?​

A)​1st field
B)​2nd field
C)3rd field
D)4th field
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
29
Match each term with its definition:

-The part of a Mac file containing file metadata and application information, such as menus, dialog boxes, icons, executable code, and controls. Also contains resource map and header information, window locations, and icons. ?

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
30
What are bad blocks, and how do you find them?​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
31
An assigned inode has _____ pointers that link to data blocks and other pointers where files are stored.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
32
Match each term with its definition:

-?A Mac file that organizes the directory hierarchy and file block mapping for File Manager.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
33
Match each term with its definition:

-An area of the Mac file system containing information from the Master Directory Block.?

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
34
Match each term with its definition:

-?The part of a Mac file containing the file's actual data, both user-created data and data written by applications, as well as a resouce map and header information, window locations, and icons.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
35
​________________ contain file and directory metadata and provide a mechanism for linking data stored in data blocks.

A)​Blocks
B)​Clusters
C)Inodes
D)Plist files
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
36
________ links are simply pointers to other files and aren't included in the link count.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
37
Where is the root user's home directory located on a Mac OS X file system?​

A)​​/ root
B)​​/ private​/ var​/ root
C)​/ private​/ spool​/ root
D)​/ home​/ root
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
38
Match each term with its definition:

-?In the Mac file system, a group of consecutive logical blocks assembled in a volume when a file is saved.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
39
Match each term with its definition:

-??A block in the Linux file system where directories and files are stored on a drive.

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
40
Match each term with its definition:

-In the Mac file system, a collection of data that can't exceed 512 bytes. Assembled in allocation blocks to store files in a volume.?

A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
41
Explain why one should have Apple factory training before attempting an acquisition on a Mac computer.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
42
​What is a plist file?
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
43
​Compare and contrast the data fork and resource fork of a Mac file.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
44
As you've learned, Linux commands use options to create variations of a command. Describe ​the rules for grouping letter arguments.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
45
Explain the differences between a hard link and a symbolic link.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
46
After making an acquisition on a Mac computer, the next step is examining the image of the file system with a forensics tool. ​Explain how to select the proper forensics tool for the task.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
47
Describe a tarball.​
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
48
UNIX and Linux ​have four components defining the file system. Identify and give a brief description of each.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 48 flashcards in this deck.