Mac and Windows Exam Review

0.0(0)
studied byStudied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/128

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:11 PM on 12/6/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

129 Terms

1
New cards

What was the first Apple computer and when?

It appeared in 1975 as an early microcomputer with basic functionality.

2
New cards

When was the Macintosh released and why important?

Released in 1985 with the first major GUI for user-friendly computing.

3
New cards

What is macOS built on?

On Darwin

4
New cards

Why is macOS related to FreeBSD important in forensics?

Many macOS tools and filesystem structures behave like BSD/Linux so Linux commands work.

5
New cards

What is MFS?

Macintosh File System used on early Macs like the Macintosh Plus.

6
New cards

What is HFS?

Hierarchical File System used on early Mac OS X with journaling quotas aliases links auto-defrag.

7
New cards

What is HFS+?

Improved file system with 32-bit allocation blocks Unicode long filenames journaling quotas links aliases per-file defrag.

8
New cards

Where are HFS+ boot blocks stored?

Sectors 0 and 1.

9
New cards

Where is the HFS+ volume header located?

Sector 2.

10
New cards

What does the HFS+ allocation file track?

Free allocation blocks.

11
New cards

What is GPT?

GUID Partition Table used on modern Macs supporting large disks.

12
New cards

What is APM?

Apple Partition Map used on old PowerPC Macs.

13
New cards

What is MBR?

Master Boot Record used on PCs with 2TB and four primary partition limits.

14
New cards

What does Boot Camp allow?

Installation of Windows alongside macOS in dual-boot.

15
New cards

Why must Boot Camp be analyzed in forensics?

Because the Mac may contain a Windows OS to analyze as well.

16
New cards

Where are macOS general logs?

/var/log/.

17
New cards

Where are macOS audit logs?

/private/var/audit/.

18
New cards

Where are macOS printer logs?

/var/spool/cups/.

19
New cards

Where are macOS swap and sleep images?

/private/var/vm/.

20
New cards

Where does macOS store update receipts?

/Library/Receipts/.

21
New cards

Where does macOS store iCloud documents?

/Library/Mobile Documents/.

22
New cards

Where is macOS bash history stored?

/Users//.bash_history.

23
New cards

Where are macOS app and user preferences stored?

/Users//Library/Preferences/.

24
New cards

Where are macOS user files stored?

/Users/.

25
New cards

What is macOS equivalent of Linux /mnt/?

/Volumes/.

26
New cards

What special directory exists only in macOS?

/private/.

27
New cards

What is the key forensic rule on evidence drives?

Never write to the original disk.

28
New cards

What is Target Disk Mode?

A Mac mode that makes it act as an external drive for forensic imaging.

29
New cards

What imaging tools work in Target Disk Mode?

dd netcat EnCase FTK.

30
New cards

Where are macOS swap files?

/var/vm/.

31
New cards

What commands help analyze macOS virtual memory?

ls ls -al grep.

32
New cards

What does macOS date command show?

Current date and timezone.

33
New cards

What does ls /dev/disk? show?

Disk devices and partitions.

34
New cards

What does hdiutil partition /dev/disk0 show?

Partition information.

35
New cards

What does system_profiler show?

Full hardware and software info.

36
New cards

Where are deleted macOS files moved first?

Trash (.Trash folder).

37
New cards

Can files be recovered after emptying Trash?

Yes from unallocated space.

38
New cards

What tools undelete Mac files?

Mac Undelete Free Undelete.

39
New cards

How to enter macOS Recovery Mode?

Hold Power+Command+R while booting.

40
New cards

Where are macOS user plist password files?

/var/db/dslocal/nodes/Default/users/.

41
New cards

What disables SIP?

csrutil disable.

42
New cards

How are modern macOS passwords cracked?

Extract plist use hashdump.py then Hashcat.

43
New cards

Why are Apple CPUs architecture-specific?

Different ISAs mean incompatible binaries.

44
New cards

Tools for reading APFS drives on Windows?

MacDrive 10 Pro APFS for Windows.

45
New cards

What is MacQuisition?

A forensic imaging tool for macOS requiring external drive.

46
New cards

What is safest way to examine a Mac?

Acquire forensic image and load read-only in VM.

47
New cards

What is core idea of Mac forensics?

Never touch original disk; analyze an image.

48
New cards

What OS introduced command-line only?

DOS in 1981.

49
New cards

Which Windows version first had a GUI?

Windows 3.x.

50
New cards

What Windows version introduced Start Menu?

Windows 95.

51
New cards

Which Windows version introduced Active Directory?

Windows 2000.

52
New cards

Which Windows version used unified NT kernel?

Windows XP.

53
New cards

Which versions added security improvements?

Vista Windows 7.

54
New cards

Which versions added touch UI?

Windows 8 and 8.1.

55
New cards

Which Windows version added biometrics and continuous updates?

Windows 10.

56
New cards

Which OS has AI integration?

Windows 11.

57
New cards

Why determine 32-bit vs 64-bit?

Tool compatibility and memory limits.

58
New cards

What is max RAM for 32-bit Windows?

4GB.

59
New cards

Why check Windows firewall?

Firewall logs show blocked or suspicious activity.

60
New cards

What encryption exists in NTFS?

EFS (Encrypted File System).

61
New cards

How many bytes in 1KB?

1024.

62
New cards

How many bytes in 1MB?

1024².

63
New cards

What does x86 mean?

32-bit Windows architecture.

64
New cards

What does x64 mean?

64-bit Windows architecture.

65
New cards

How much memory can 64-bit address?

Up to 16 exabytes.

66
New cards

What is first Windows boot stage?

POST.

67
New cards

What does MBR do?

Identifies partitions and boot loader.

68
New cards

What loads after boot sector?

NTLDR.

69
New cards

What happens if hiberfil.sys is found at boot?

System resumes from hibernation.

70
New cards

What mode does NTLDR switch?

Real mode to protected 32/64-bit mode.

71
New cards

What drivers load next?

FAT FAT32 NTFS drivers.

72
New cards

What file is the Windows kernel?

ntoskrnl.exe.

73
New cards

What file abstracts hardware?

hal.dll.

74
New cards

What loads the Windows system hive?

Registry initialization.

75
New cards

What displays login screen?

Win32 subsystem and winlogon.exe.

76
New cards

What is hibernation?

Saving RAM to disk and powering off.

77
New cards

What is sleep?

Low-power mode keeping RAM active.

78
New cards

What is a snapshot?

Saved system state.

79
New cards

What does ntdetect.com do?

Collects hardware info at boot.

80
New cards

What is ntbootdd.sys?

Storage controller driver.

81
New cards

What is hal.dll?

Hardware Abstraction Layer.

82
New cards

What is smss.exe?

Session Manager Subsystem.

83
New cards

What is winlogon.exe?

Controls login processes.

84
New cards

What is lsass.exe?

Local Security Authority for authentication.

85
New cards

What is explorer.exe?

Windows desktop shell.

86
New cards

What is csrss.exe?

Client/Server Runtime Subsystem managing console.

87
New cards

What does $attrdef do?

Defines NTFS attribute types.

88
New cards

What does $badclus do?

Tracks bad disk sectors.

89
New cards

What does $bitmap do?

Tracks used and free clusters.

90
New cards

What does $boot contain?

Volume boot information.

91
New cards

What is $mft?

Master File Table.

92
New cards

What is $mftmirr?

Mirror of first four MFT entries.

93
New cards

What does $quota store?

User disk quota info.

94
New cards

What does $volume store?

Volume name and version.

95
New cards

What does fsutil do?

Displays filesystem info.

96
New cards

What are the steps of volatile memory analysis?

  1. Start trusted command shell.

  2. Prepare data collection system.

  3. Capture memory dump.

  4. Compute hash.

  5. Analyze memory offline.

97
New cards

What is stack memory?

LIFO storage for function calls and local variables.

98
New cards

What is heap memory?

Dynamically allocated memory persistent between functions.

99
New cards

What does pslist do?

Lists processes.

100
New cards

What does psinfo show?

System uptime and details.