Command Line
Operating Systems
Files + Folders
Software
Hardware
100

This is the default shell type on most Linux distributions.

What is bash (Bourne Again Shell)?

100

This operating system version will go end of life in October 2025. At one point this OS had over 1.4 billion users and comprised most of the workstation market share in the world.

What is Windows 10?

100

The symbol ~ represents this file path on Linux.

The home directory for the current user.

100

Although installed on and most commonly associated with Windows, this authentication and authorization software can also work with Linux and Mac computers.

What is Active Directory?

100

Known as volatile memory, this type of memory disappears when powered off. Incident Responders should capture this type of memory first before performing an incident investigation or powering off a compromised server.

What is Random Access Memory (RAM)?

200

This is the default shell type on most MacOS distributions.

What is Zsh (Z shell)?

200

Kali Linux is based on this Linux distribution.

What is Debian?

200

This Linux folder is adequately named for storing temporarily files that are frequently deleted, making it a common place for attackers to put their malicious files. 

What is /tmp?

200

This is a native Endpoint Detection and Response software on a popular OS.

What is Microsoft Defender for Endpoint?

200

Systems with this hardware component are often targeted in crypto-mining attacks.

What is a GPU (Graphics Processing Unit)?

300

This reconnaissance tactic can be performed with the command "net users /domain".

What is enumeration?

300

This operating system is only supported for the last three versions. A new version of the operating system is released every fall.

What is MacOS?

300

A user's bash history is stored at this file path.

What is /home/user/.bash_history?

300

This application communicates with the operating system network stack to assign the originating port on your computer when connecting to a website.

What is a web browser?

300

The Spectre and Meltdown vulnerabilities affected this computer hardware component, allowing attackers to steal data from the computer memory.

What is the CPU (Computer Processing Unit)?

400

This command line language is recognized by its use of cmdlets, a command created out of an Action-Verb.

What is PowerShell?

400

This is a paid, commercial, enterprise distribution of Linux that was based on the previously open source distribution of CentOS.

What is Red Hat Enterprise Linux (RHEL)?

400

This file path is the default index directory for Apache web server on Linux.

What is /var/www/html?

400

This user-friendly firewall configuration tool, developed for Ubuntu, simplifies managing iptables with easy-to-use commands like allow, deny, and enable.

What is Unified FireWall (UFW)?

400

This parent company only permits virtualization of their operating system on hardware created by the parent company. Running the parent company's OS on non-parent company hardware is strictly prohibited.

Who is Apple?

500

A reference to this outdated command line language is found in the byte-to-ASCII translation at the beginning of .exe files.

What is MS-DOS?

500

This controversial feature in Windows 11 routinely takes screenshots of your desktop and archives the information for future retrieval. Critics call the features a "treasure trove" for attackers.

What is Windows Recall?

500

The user's shell type and access is stored in this file on most Linux distributions. This file details if a user is allowed to log on to the system interactively, and if the user is authorized for a shell on the system.

What is /etc/passwd?

500

This ticket type in Kerberos is abused in a Golden Ticket attack in order to provide an attacker complete access to any service within the domain.

What is a Ticket Granting Ticket (TGT)?

500

Often installed directly onto the motherboard, this is a security chip solely designed to enhance computer security by securely storing cryptographic keys and other sensitive information.

What is a Trusted Platform Module (TPM)?

M
e
n
u