Podcast
Questions and Answers
Which operating system was developed as a replacement for Apple DOS 3.3 and had more support for programming, including assembly and BASIC?
Which operating system was developed as a replacement for Apple DOS 3.3 and had more support for programming, including assembly and BASIC?
What was the name of the first edition of the Apple DOS released in 1978?
What was the name of the first edition of the Apple DOS released in 1978?
Which Apple II model was the first to feature color graphics in a plastic case with a built-in keyboard?
Which Apple II model was the first to feature color graphics in a plastic case with a built-in keyboard?
What was the acronym SOS in Apple SOS operating system stood for?
What was the acronym SOS in Apple SOS operating system stood for?
Signup and view all the answers
Which Apple II model was released as a 16-bit computer, unlike its predecessors which were 8-bit?
Which Apple II model was released as a 16-bit computer, unlike its predecessors which were 8-bit?
Signup and view all the answers
Which operating system had a full graphical user interface with a file browser navigated with mouse clicks?
Which operating system had a full graphical user interface with a file browser navigated with mouse clicks?
Signup and view all the answers
What is the main reason many forensic examiners lack a good working knowledge of Mac OS systems?
What is the main reason many forensic examiners lack a good working knowledge of Mac OS systems?
Signup and view all the answers
Who were the three founders of Apple Computer?
Who were the three founders of Apple Computer?
Signup and view all the answers
What was the first computer created by Wozniak for Apple Computer?
What was the first computer created by Wozniak for Apple Computer?
Signup and view all the answers
Which company originally had the right of first refusal on any new inventions by Steve Wozniak?
Which company originally had the right of first refusal on any new inventions by Steve Wozniak?
Signup and view all the answers
How fast was the 8-bit microprocessor in the first Apple computer running?
How fast was the 8-bit microprocessor in the first Apple computer running?
Signup and view all the answers
What technology did Steve Wozniak's employment contract with Hewlett-Packard lead to being released to him?
What technology did Steve Wozniak's employment contract with Hewlett-Packard lead to being released to him?
Signup and view all the answers
What was the main change with the introduction of Mac OS X?
What was the main change with the introduction of Mac OS X?
Signup and view all the answers
Which product introduced by Apple did not perform well in the market and was discontinued in 1997?
Which product introduced by Apple did not perform well in the market and was discontinued in 1997?
Signup and view all the answers
What was the operating system for the Macintosh computer initially released by Apple in January 1984?
What was the operating system for the Macintosh computer initially released by Apple in January 1984?
Signup and view all the answers
Which processor speed did the Macintosh have when it was released in January 1984?
Which processor speed did the Macintosh have when it was released in January 1984?
Signup and view all the answers
What distinguished the Macintosh II from its predecessor, the Macintosh?
What distinguished the Macintosh II from its predecessor, the Macintosh?
Signup and view all the answers
In what year did Apple release the Apple Network Server with a variation of the IBM AIX system?
In what year did Apple release the Apple Network Server with a variation of the IBM AIX system?
Signup and view all the answers
When did Apple change the operating system brand name to macOS?
When did Apple change the operating system brand name to macOS?
Signup and view all the answers
Which Mac OS version introduced Handoff, allowing interaction between iPhones and Mac OS computers?
Which Mac OS version introduced Handoff, allowing interaction between iPhones and Mac OS computers?
Signup and view all the answers
What was the main focus of Mac OS X 10.6, Snow Leopard, upon its release in 2009?
What was the main focus of Mac OS X 10.6, Snow Leopard, upon its release in 2009?
Signup and view all the answers
Which Mac OS version was the last to be named after animals?
Which Mac OS version was the last to be named after animals?
Signup and view all the answers
What was one significant change in Mac OS X v10.7, Lion, regarding its interface?
What was one significant change in Mac OS X v10.7, Lion, regarding its interface?
Signup and view all the answers
Which Mac OS version allowed users to complete unfinished iPhone emails on their Mac OS computer?
Which Mac OS version allowed users to complete unfinished iPhone emails on their Mac OS computer?
Signup and view all the answers
What technology supported by Big Sur helps ease the transition to Apple's silicon processor architecture?
What technology supported by Big Sur helps ease the transition to Apple's silicon processor architecture?
Signup and view all the answers
Which Mac OS version included built-in support for iCloud to support cloud computing?
Which Mac OS version included built-in support for iCloud to support cloud computing?
Signup and view all the answers
Which file system used concepts from the SOS operating system designed for the Apple III?
Which file system used concepts from the SOS operating system designed for the Apple III?
Signup and view all the answers
Which file system introduced to support Apple's new hard drive in 1985?
Which file system introduced to support Apple's new hard drive in 1985?
Signup and view all the answers
Which file system supported filenames of up to 255 characters, unlike the DOS system?
Which file system supported filenames of up to 255 characters, unlike the DOS system?
Signup and view all the answers
Which file system was an enhancement of the HFS file system?
Which file system was an enhancement of the HFS file system?
Signup and view all the answers
Which file system replaced the HFS file system with Mac OS 8.1?
Which file system replaced the HFS file system with Mac OS 8.1?
Signup and view all the answers
Which file system feature keeps a record of file transactions to aid in file recovery after a crash?
Which file system feature keeps a record of file transactions to aid in file recovery after a crash?
Signup and view all the answers
What type of link in HFS+ is an inode linking directly to a specific file?
What type of link in HFS+ is an inode linking directly to a specific file?
Signup and view all the answers
Which file system uses Unicode for file naming information encoding?
Which file system uses Unicode for file naming information encoding?
Signup and view all the answers
When does an HFS+ file get defragmented upon opening?
When does an HFS+ file get defragmented upon opening?
Signup and view all the answers
What storage system used in HFS+ keeps track of free and in-use allocation blocks?
What storage system used in HFS+ keeps track of free and in-use allocation blocks?
Signup and view all the answers
Which Mac OS feature allows execution of Linux commands through a BASH shell prompt?
Which Mac OS feature allows execution of Linux commands through a BASH shell prompt?
Signup and view all the answers
In HFS+, what is a significant difference compared to HFS regarding allocation blocks?
In HFS+, what is a significant difference compared to HFS regarding allocation blocks?
Signup and view all the answers
What file system is used by DVD-ROM discs?
What file system is used by DVD-ROM discs?
Signup and view all the answers
What is a key feature of APFS in comparison to HFS+?
What is a key feature of APFS in comparison to HFS+?
Signup and view all the answers
Which partition scheme is used primarily with computers that have an Intel-based processor?
Which partition scheme is used primarily with computers that have an Intel-based processor?
Signup and view all the answers
Which file system is associated with CDs?
Which file system is associated with CDs?
Signup and view all the answers
What utility allows one to install additional operating systems alongside Mac OS in a nondestructive manner?
What utility allows one to install additional operating systems alongside Mac OS in a nondestructive manner?
Signup and view all the answers
What type of drive partition can Mac OS read with read-only support?
What type of drive partition can Mac OS read with read-only support?
Signup and view all the answers
What does the Apple Partition Map work with?
What does the Apple Partition Map work with?
Signup and view all the answers
Which Apple device is likely to use APFS as its file system?
Which Apple device is likely to use APFS as its file system?
Signup and view all the answers
Which partition scheme requires OS X v10.4 or later?
Which partition scheme requires OS X v10.4 or later?
Signup and view all the answers
Which file system has specific extensions developed by Apple?
Which file system has specific extensions developed by Apple?
Signup and view all the answers
What should you not create if the system is using APFS according to the text?
What should you not create if the system is using APFS according to the text?
Signup and view all the answers
In Mac OS, support for which file system allows reading floppy disks?
In Mac OS, support for which file system allows reading floppy disks?
Signup and view all the answers
What type of information can be found in the /var/spool/cups folder in Mac OS logs?
What type of information can be found in the /var/spool/cups folder in Mac OS logs?
Signup and view all the answers
Which log in Mac OS provides data on all mounted volumes, including the dates they were mounted?
Which log in Mac OS provides data on all mounted volumes, including the dates they were mounted?
Signup and view all the answers
In Mac OS, which folder can give information about devices that have been attached and data from them?
In Mac OS, which folder can give information about devices that have been attached and data from them?
Signup and view all the answers
What is the significance of the /private/var/audit logs in Mac OS forensics?
What is the significance of the /private/var/audit logs in Mac OS forensics?
Signup and view all the answers
Which log directory in Mac OS is similar to Linux file structures due to its FreeBSD base?
Which log directory in Mac OS is similar to Linux file structures due to its FreeBSD base?
Signup and view all the answers
Why is checking logs considered one of the first steps in any forensic examination?
Why is checking logs considered one of the first steps in any forensic examination?
Signup and view all the answers
Where can important forensic data be found in Mac OS audit logs?
Where can important forensic data be found in Mac OS audit logs?
Signup and view all the answers
Which folder in Mac OS contains user preferences, including preferences of deleted programs?
Which folder in Mac OS contains user preferences, including preferences of deleted programs?
Signup and view all the answers
In which folder of Mac OS can you find lists of recently opened applications and temporary data used by applications?
In which folder of Mac OS can you find lists of recently opened applications and temporary data used by applications?
Signup and view all the answers
Where would you look to find items saved to iCloud in Mac OS?
Where would you look to find items saved to iCloud in Mac OS?
Signup and view all the answers
Which folder in Mac OS is less useful for forensic investigation but can indicate if a patch was applied and when?
Which folder in Mac OS is less useful for forensic investigation but can indicate if a patch was applied and when?
Signup and view all the answers
Where can you find a log showing a variety of commands executed in the terminal window of Mac OS?
Where can you find a log showing a variety of commands executed in the terminal window of Mac OS?
Signup and view all the answers
Where can a forensic examiner find information about mounted devices in Mac OS?
Where can a forensic examiner find information about mounted devices in Mac OS?
Signup and view all the answers
Which Mac OS directory should a forensic examiner check primarily for user accounts and associated files?
Which Mac OS directory should a forensic examiner check primarily for user accounts and associated files?
Signup and view all the answers
In a forensic examination of a Mac machine, where would an examiner look for network properties and servers information?
In a forensic examination of a Mac machine, where would an examiner look for network properties and servers information?
Signup and view all the answers
Which Mac OS directory is particularly important to check in cases involving malware?
Which Mac OS directory is particularly important to check in cases involving malware?
Signup and view all the answers
Where are configuration files typically located in a Mac OS system that could be of interest in a forensic investigation?
Where are configuration files typically located in a Mac OS system that could be of interest in a forensic investigation?
Signup and view all the answers
If an examiner needs data regarding mounted devices like CDs and external disks in Mac OS, which directory should they explore?
If an examiner needs data regarding mounted devices like CDs and external disks in Mac OS, which directory should they explore?
Signup and view all the answers
Where is the network configuration data for each network card stored in Mac OS?
Where is the network configuration data for each network card stored in Mac OS?
Signup and view all the answers
Which Mac OS directory is essential for examining user accounts and associated files?
Which Mac OS directory is essential for examining user accounts and associated files?
Signup and view all the answers
Where can an examiner find information about servers, network libraries, and network properties in Mac OS?
Where can an examiner find information about servers, network libraries, and network properties in Mac OS?
Signup and view all the answers
In which Mac OS directory are configuration files located, often manipulated by cybercriminals?
In which Mac OS directory are configuration files located, often manipulated by cybercriminals?
Signup and view all the answers
Where does an examiner need to look to find information on mounted devices like CDs and external disks in Mac OS?
Where does an examiner need to look to find information on mounted devices like CDs and external disks in Mac OS?
Signup and view all the answers
Which directory in Mac OS stores applications and is particularly critical to check in cases involving malware?
Which directory in Mac OS stores applications and is particularly critical to check in cases involving malware?
Signup and view all the answers
What is one advantage of using Target Disk Mode in a Mac OS forensic investigation?
What is one advantage of using Target Disk Mode in a Mac OS forensic investigation?
Signup and view all the answers
Which tool can be used in Mac OS forensics to create a bit-level copy of a suspect drive?
Which tool can be used in Mac OS forensics to create a bit-level copy of a suspect drive?
Signup and view all the answers
In Mac OS forensics, what command can be used along with netcat to make a forensic copy of a drive?
In Mac OS forensics, what command can be used along with netcat to make a forensic copy of a drive?
Signup and view all the answers
What is the primary benefit of placing the suspect computer into Target Disk Mode during imaging?
What is the primary benefit of placing the suspect computer into Target Disk Mode during imaging?
Signup and view all the answers
What differentiates Target Disk Mode from traditional imaging tools like EnCase or Forensic Toolkit in Mac OS forensics?
What differentiates Target Disk Mode from traditional imaging tools like EnCase or Forensic Toolkit in Mac OS forensics?
Signup and view all the answers
Which option correctly describes the process of connecting to a suspect computer in Target Disk Mode?
Which option correctly describes the process of connecting to a suspect computer in Target Disk Mode?
Signup and view all the answers
What is the purpose of using the ls -al command in a Mac OS forensic examination?
What is the purpose of using the ls -al command in a Mac OS forensic examination?
Signup and view all the answers
Which command should a forensic examiner use to list the device files that are currently in use on a Mac machine?
Which command should a forensic examiner use to list the device files that are currently in use on a Mac machine?
Signup and view all the answers
In Mac OS forensics, what information can be obtained using the system_profiler SPHardwareDataType command?
In Mac OS forensics, what information can be obtained using the system_profiler SPHardwareDataType command?
Signup and view all the answers
Which directory in Mac OS is particularly important to check for user accounts and associated files during a forensic investigation?
Which directory in Mac OS is particularly important to check for user accounts and associated files during a forensic investigation?
Signup and view all the answers
What type of information does the date command provide in a Mac OS forensic examination?
What type of information does the date command provide in a Mac OS forensic examination?
Signup and view all the answers
Why is it essential to know the partitions recognized by a Mac machine upon boot-up in a forensic examination?
Why is it essential to know the partitions recognized by a Mac machine upon boot-up in a forensic examination?
Signup and view all the answers
What is the purpose of using the ls -al command in a Mac OS forensic examination?
What is the purpose of using the ls -al command in a Mac OS forensic examination?
Signup and view all the answers
What information does the date command provide in a forensic examination on a Mac OS?
What information does the date command provide in a forensic examination on a Mac OS?
Signup and view all the answers
Which command should a forensic examiner use to list the device files that are currently in use on a Mac machine?
Which command should a forensic examiner use to list the device files that are currently in use on a Mac machine?
Signup and view all the answers
Why is it important to document the information from the ls /dev/disk? command before shutting down a Mac system for transport to a forensic lab?
Why is it important to document the information from the ls /dev/disk? command before shutting down a Mac system for transport to a forensic lab?
Signup and view all the answers
What type of information does the system_profiler SPHardwareDataType command return in a forensic examination on a Mac OS?
What type of information does the system_profiler SPHardwareDataType command return in a forensic examination on a Mac OS?
Signup and view all the answers
In Mac OS forensics, what does the grep search tool allow an examiner to do in the virtual memory folder?
In Mac OS forensics, what does the grep search tool allow an examiner to do in the virtual memory folder?
Signup and view all the answers
Which folder in Mac OS contains the swap file/virtual memory?
Which folder in Mac OS contains the swap file/virtual memory?
Signup and view all the answers
How can a forensic examiner check the partitions recognized by a Mac machine upon boot-up?
How can a forensic examiner check the partitions recognized by a Mac machine upon boot-up?
Signup and view all the answers
What is a significant advantage of using shell commands in Mac OS forensic examinations?
What is a significant advantage of using shell commands in Mac OS forensic examinations?
Signup and view all the answers
What does the hdiutil partition /dev/disk0 command primarily help in listing during a forensic examination of a Mac system?
What does the hdiutil partition /dev/disk0 command primarily help in listing during a forensic examination of a Mac system?
Signup and view all the answers
What is a critical step to remember when mounting a forensic image as a VM?
What is a critical step to remember when mounting a forensic image as a VM?
Signup and view all the answers
Which software mentioned allows the creation of a VM from a forensic image?
Which software mentioned allows the creation of a VM from a forensic image?
Signup and view all the answers
In Mac OS forensics, what is the purpose of converting a forensic image to a VM?
In Mac OS forensics, what is the purpose of converting a forensic image to a VM?
Signup and view all the answers
Which tool allows mounting forensic images as read-only VMs using the VM of your choice?
Which tool allows mounting forensic images as read-only VMs using the VM of your choice?
Signup and view all the answers
What technique is recommended to examine directories and execute BASH commands in Mac OS forensics when standard tools are insufficient?
What technique is recommended to examine directories and execute BASH commands in Mac OS forensics when standard tools are insufficient?
Signup and view all the answers