What is the difference between protection and security in OS terminology?
Q2
A web server process runs as root "because it was easier". Which principle is violated, and why does it matter?
Q3
An access control list stores:
Q4
Why is revocation easier with ACLs than with capabilities?
Q5
After fd = open("grades.txt", O_RDONLY) succeeds, the file's permissions are changed to 000. Can the process still read through fd?
Q6
What is the octal form of rwxr-x---?
Q7
A file is owned by ana (group staff) with mode 640. Ben is in group staff. Which operations can Ben perform?
Q8
A file owned by ana has mode 044 (---r--r--). Can ana read it?
Q9
With umask 027, what permissions does a newly created directory get?
Q10
Why is a setuid-root program a security risk?
Q11
A program only needs to listen on port 443. What is the least-privilege way to allow it on Linux?
Q12
Bell–LaPadula levels: Public < Confidential < Secret. A Confidential analyst tries to write into a Public brochure. Allowed?
Q13
In the same Bell–LaPadula system, can the Confidential analyst read the Secret exams?
Q14
Under the Biba integrity model, which access is denied?
Q15
What distinguishes mandatory access control (SELinux) from discretionary access control (Unix permissions)?
Q16
Why does each stored password hash use a random salt?
Q17
How many possible 8-character passwords made of lowercase letters exist, and how long does an offline attacker at 10¹⁰ guesses/s need on average?
Q18
Why do systems use deliberately slow password hashes (bcrypt, scrypt, Argon2)?
Q19
Which OS/hardware defense makes injected code on the stack impossible to execute?
Q20
What does ASLR randomize, and why?
Q21
Which is the most effective protection against losing data to ransomware?
Q22
What does seccomp do for a sandboxed process?
Q23
Why are secure boot and a TPM especially important for edge servers?
Q24
What is the core idea of zero trust?
Q25
Which authentication method best resists phishing and password-database theft?
Q26
What do trusted execution environments (Intel SGX/TDX, AMD SEV) protect against in the cloud?
Q27
Why do memory-safe languages (Java, Rust, Go) reduce OS-level security incidents?
Q28Short answer
Compute, for each case, the octal mode or the decision: (a) rwxr-xr-- in octal; (b) the mode of a new file and a new directory with umask 022 and with umask 077; (c) ana (groups staff) writes a file ana:staff mode 640; (d) ben (groups staff) writes the same file; (e) eve (groups guests) reads it; (f) ana reads a file ana:staff mode 044. Explain (f).
Q29Short answer
EdgeCampus stores student-account password hashes. An attacker steals the database. Compare (a) unsalted MD5 and (b) salted bcrypt (cost 12) in terms of what the attacker can do. Then compute the average cracking time for random 8-character passwords over 62 symbols with 10¹⁰ MD5 guesses/s and 10⁴ bcrypt guesses/s, and propose a password and authentication policy.
Q30Short answer
Build a short threat model for EdgeCampus (phones with CampusAR, building edge servers, public cloud). Identify at least four threats (using STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) and, for each, an OS- or system-level countermeasure from this course.