Deck 7: Macintosh and Linux Boot Processes and File Systems
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/48
Play
Full screen (f)
Deck 7: Macintosh and Linux Boot Processes and File Systems
1
What file is used to store any file information that is not in the MDB or a VCB?
A)page file
B)metadata database file
C)slack file
D)extents overflow file
A)page file
B)metadata database file
C)slack file
D)extents overflow file
D
2
Adding the _____________ flag to the ls -l command has the effect of of showing all files beginning with the "." character in addition to other files.
A)-s
B)-d
C)-l
D)-a
A)-s
B)-d
C)-l
D)-a
D
3
If a file has 510 bytes of data, what is byte 510?
A)The physical EOF.
B)The logical EOF.
C)The terminating EOF.
D)The end of the sector.
A)The physical EOF.
B)The logical EOF.
C)The terminating EOF.
D)The end of the sector.
B
4
What command below will create a symbolic link to a file?
A)ln -s
B)ls -ia
C)ln -l
D)ls -h
A)ln -s
B)ls -ia
C)ln -l
D)ls -h
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
5
Capitalization, or lack thereof, makes no difference with UNIX and Linux commands.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
6
Select below the command that can be used to display bad block information on a Linux file system, but also has the capability to destroy valuable information.
A)dd
B)fdisk
C)badblocks
D)mke2fs
A)dd
B)fdisk
C)badblocks
D)mke2fs
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
7
The Mac OS reduces file fragmentation by using _______________.
A)inodes
B)superblocks
C)clumps
D)chunks
A)inodes
B)superblocks
C)clumps
D)chunks
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
8
Who is the current maintainer of the Linux kernel?
A)Tim Cook
B)Eric Shmidt
C)Linus Torvalds
D)Lennart Poettering
A)Tim Cook
B)Eric Shmidt
C)Linus Torvalds
D)Lennart Poettering
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
9
The term "kernel" is often used when discussing Linux because technically, Linus is only the core of the OS.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
10
What type of block does a UNIX/ Linux computer only have one of?
A)boot block
B)data block
C)inode block
D)superblock
A)boot block
B)data block
C)inode block
D)superblock
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
11
In a B*-tree file system, what node stores link information to previous and next nodes?
A)inode
B)header node
C)index node
D)map node
A)inode
B)header node
C)index node
D)map node
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
12
Linux is a certified UNIX operating system.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
13
The ______________ command can be used to see network interfaces.
A)ifconfig
B)ipconfig
C)show interfaces
D)show ip brief
A)ifconfig
B)ipconfig
C)show interfaces
D)show ip brief
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
14
________________ is a specialized carving tool that can read many image file formats, such as RAW and Expert Witness.
A)AccessData FTK
B)X-Ways Forensics
C)Guidance Software EnCase
D)Foremost
A)AccessData FTK
B)X-Ways Forensics
C)Guidance Software EnCase
D)Foremost
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
15
What file under the / etc folder contains the hashed passwords for a local system?
A)passwd
B)hashes
C)shadow
D)users
A)passwd
B)hashes
C)shadow
D)users
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
16
On Mac OS X systems, what utility can be used to encrypt / decrypt a user's home directory?
A)Disk Utility
B)BitLocker
C)FileVault
D)iCrypt
A)Disk Utility
B)BitLocker
C)FileVault
D)iCrypt
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
17
The only pieces of metadata not in an inode are the filename and path.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
18
In UNIX and Linux, everything except monitors are considered files.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
19
What is the minimum size of a block in UNIX/ Linux filesystems?
A)128 bytes
B)512 bytes
C)1024 bits
D)2048 bits
A)128 bytes
B)512 bytes
C)1024 bits
D)2048 bits
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
20
As part of a forensics investigation, you need to recover the logon and logoff history information on a Linux based OS. Where can this information be found?
A)/ var/ log/ utmp
B)/ var/ log/ wtmp
C)/ var/ log/ userlog
D)/ var/ log/ system.log
A)/ var/ log/ utmp
B)/ var/ log/ wtmp
C)/ var/ log/ userlog
D)/ var/ log/ system.log
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
21
Match each term with its definition:
-?A node that stores information about B*-tree file.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-?A node that stores information about B*-tree file.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
22
Match each term with its definition:
-?A key part of the Linux file system, these informatuin nodes contain descriptive file or directory data, such as UIDS, GIDs, modification times, access times, creation times, and file locations.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-?A key part of the Linux file system, these informatuin nodes contain descriptive file or directory data, such as UIDS, GIDs, modification times, access times, creation times, and file locations.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
23
Since Mac OS 8.6, _______________ have been available for use in managing passwords for applications, web sites, and other system files.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
24
A hash that begins with "$6" in the shadow file indicates that it is a hash from what hashing algorithm?
A)MD5
B)Blowfish
C)SHA-1
D)SHA-512
A)MD5
B)Blowfish
C)SHA-1
D)SHA-512
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
25
Linux supports a wide range of file systems. Distinguish the three Extended File Systems of Linux.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
26
What information below is not included within an inode??
A)?The mode and type of the file or directory
B)?The number of links to a file or directory
C)The file's or directory's last access time and last modified time
D)The file's or directory's path
A)?The mode and type of the file or directory
B)?The number of links to a file or directory
C)The file's or directory's last access time and last modified time
D)The file's or directory's path
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
27
Match each term with its definition:
-?A block in the Linux file system that specifies and keep tracks of the disk geometry and available space and manages the file system.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-?A block in the Linux file system that specifies and keep tracks of the disk geometry and available space and manages the file system.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
28
Within the / etc/ shadow file, what field contains the password hash for a user account if one exists?
A)1st field
B)2nd field
C)3rd field
D)4th field
A)1st field
B)2nd field
C)3rd field
D)4th field
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
29
Match each term with its definition:
-The part of a Mac file containing file metadata and application information, such as menus, dialog boxes, icons, executable code, and controls. Also contains resource map and header information, window locations, and icons. ?
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-The part of a Mac file containing file metadata and application information, such as menus, dialog boxes, icons, executable code, and controls. Also contains resource map and header information, window locations, and icons. ?
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
30
What are bad blocks, and how do you find them?
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
31
An assigned inode has _____ pointers that link to data blocks and other pointers where files are stored.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
32
Match each term with its definition:
-?A Mac file that organizes the directory hierarchy and file block mapping for File Manager.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-?A Mac file that organizes the directory hierarchy and file block mapping for File Manager.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
33
Match each term with its definition:
-An area of the Mac file system containing information from the Master Directory Block.?
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-An area of the Mac file system containing information from the Master Directory Block.?
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
34
Match each term with its definition:
-?The part of a Mac file containing the file's actual data, both user-created data and data written by applications, as well as a resouce map and header information, window locations, and icons.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-?The part of a Mac file containing the file's actual data, both user-created data and data written by applications, as well as a resouce map and header information, window locations, and icons.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
35
________________ contain file and directory metadata and provide a mechanism for linking data stored in data blocks.
A)Blocks
B)Clusters
C)Inodes
D)Plist files
A)Blocks
B)Clusters
C)Inodes
D)Plist files
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
36
________ links are simply pointers to other files and aren't included in the link count.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
37
Where is the root user's home directory located on a Mac OS X file system?
A)/ root
B)/ private/ var/ root
C)/ private/ spool/ root
D)/ home/ root
A)/ root
B)/ private/ var/ root
C)/ private/ spool/ root
D)/ home/ root
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
38
Match each term with its definition:
-?In the Mac file system, a group of consecutive logical blocks assembled in a volume when a file is saved.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-?In the Mac file system, a group of consecutive logical blocks assembled in a volume when a file is saved.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
39
Match each term with its definition:
-??A block in the Linux file system where directories and files are stored on a drive.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-??A block in the Linux file system where directories and files are stored on a drive.
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
40
Match each term with its definition:
-In the Mac file system, a collection of data that can't exceed 512 bytes. Assembled in allocation blocks to store files in a volume.?
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
-In the Mac file system, a collection of data that can't exceed 512 bytes. Assembled in allocation blocks to store files in a volume.?
A)B*-tree
B)data block
C)logical block
D)inodes
E)Volume Control Block
F)Allocation Block
G)header node
H)data fork
I)superblock
J)resource fork
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
41
Explain why one should have Apple factory training before attempting an acquisition on a Mac computer.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
42
What is a plist file?
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
43
Compare and contrast the data fork and resource fork of a Mac file.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
44
As you've learned, Linux commands use options to create variations of a command. Describe the rules for grouping letter arguments.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
45
Explain the differences between a hard link and a symbolic link.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
46
After making an acquisition on a Mac computer, the next step is examining the image of the file system with a forensics tool. Explain how to select the proper forensics tool for the task.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
47
Describe a tarball.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck
48
UNIX and Linux have four components defining the file system. Identify and give a brief description of each.
Unlock Deck
Unlock for access to all 48 flashcards in this deck.
Unlock Deck
k this deck