THINK FIRST·CODE LATER

← Operating Systems
Chapter 14 · Week 15

Protection and Security: From File Permissions to Zero-Trust Edge

Answered 0/30 Correct 0
Sign in to save progress across devices
Q1

What is the difference between protection and security in OS terminology?

Q2

A web server process runs as root "because it was easier". Which principle is violated, and why does it matter?

Q3

An access control list stores:

Q4

Why is revocation easier with ACLs than with capabilities?

Q5

After fd = open("grades.txt", O_RDONLY) succeeds, the file's permissions are changed to 000. Can the process still read through fd?

Q6

What is the octal form of rwxr-x---?

Q7

A file is owned by ana (group staff) with mode 640. Ben is in group staff. Which operations can Ben perform?

Q8

A file owned by ana has mode 044 (---r--r--). Can ana read it?

Q9

With umask 027, what permissions does a newly created directory get?

Q10

Why is a setuid-root program a security risk?

Q11

A program only needs to listen on port 443. What is the least-privilege way to allow it on Linux?

Q12

Bell–LaPadula levels: Public < Confidential < Secret. A Confidential analyst tries to write into a Public brochure. Allowed?

Q13

In the same Bell–LaPadula system, can the Confidential analyst read the Secret exams?

Q14

Under the Biba integrity model, which access is denied?

Q15

What distinguishes mandatory access control (SELinux) from discretionary access control (Unix permissions)?

Q16

Why does each stored password hash use a random salt?

Q17

How many possible 8-character passwords made of lowercase letters exist, and how long does an offline attacker at 10¹⁰ guesses/s need on average?

Q18

Why do systems use deliberately slow password hashes (bcrypt, scrypt, Argon2)?

Q19

Which OS/hardware defense makes injected code on the stack impossible to execute?

Q20

What does ASLR randomize, and why?

Q21

Which is the most effective protection against losing data to ransomware?

Q22

What does seccomp do for a sandboxed process?

Q23

Why are secure boot and a TPM especially important for edge servers?

Q24

What is the core idea of zero trust?

Q25

Which authentication method best resists phishing and password-database theft?

Q26

What do trusted execution environments (Intel SGX/TDX, AMD SEV) protect against in the cloud?

Q27

Why do memory-safe languages (Java, Rust, Go) reduce OS-level security incidents?

Q28 Short answer

Compute, for each case, the octal mode or the decision: (a) rwxr-xr-- in octal; (b) the mode of a new file and a new directory with umask 022 and with umask 077; (c) ana (groups staff) writes a file ana:staff mode 640; (d) ben (groups staff) writes the same file; (e) eve (groups guests) reads it; (f) ana reads a file ana:staff mode 044. Explain (f).

Q29 Short answer

EdgeCampus stores student-account password hashes. An attacker steals the database. Compare (a) unsalted MD5 and (b) salted bcrypt (cost 12) in terms of what the attacker can do. Then compute the average cracking time for random 8-character passwords over 62 symbols with 10¹⁰ MD5 guesses/s and 10⁴ bcrypt guesses/s, and propose a password and authentication policy.

Q30 Short answer

Build a short threat model for EdgeCampus (phones with CampusAR, building edge servers, public cloud). Identify at least four threats (using STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) and, for each, an OS- or system-level countermeasure from this course.