05 Flashcards

1
Q

____________ before OS starts, firmware and system configurations are used to locate and load the second stage boot loader which is called?

A

Pre-Boot
BootMGR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

_________ windows boot programs are used to locate and load the kernel and its dependencies

A

Boot

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

_________ kernel is initialized

A

kernel initialization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

_________ user mode system processes start

A

User Mode Startup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the order of steps of Boot Phase? 1-5

1-5 PBWD0x

A

Switches from real to protected mode (protected mode)
Reads BCD (BCD)
Starts winload.exe (winload,exe)
Loads the Ntoskrnl.exe and Hal.dll (Ntoskrnl)
Starts the drivers with start values of (0x0)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the order of steps for the kernel initialization phase? 6-9

6-9 MHDS

A

Ntdll.dll is mapped into address space (Mapped)
Creates HKLM\Hardware (HKLM)
starts drivers with start values of (0x1) (drivers)
stars smss.exe (0) process (smss.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the start value for each of the following?
0x0 _____
0x1 _____
0x2 _______
0x3 ______
0x4 ______

A

Boot
System
Automatic
Manuel
Disabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does eaxh type value tell us about a service?
0x10
0x20

A

Has its own executable
is a library and relies on svchost.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly