Other platforms
Everything outside the Linux and BSD families — Windows and macOS on desktop and server, plus small embedded boards. Relevant whenever a role involves cross-platform support or hardware-adjacent work.
on this pageshowhide
explore
- Windows30 questions
- NT Architecture5 questions
- Processes and Threads6 questions
- Registry and Services6 questions
- NTFS and ACLs5 questions
- PowerShell Administration3 questions
- WSL and Linux Interop5 questions
- macOS35 questions
- Darwin/XNU Kernel5 questions
- launchd & Services6 questions
- APFS Filesystem6 questions
- Security Model6 questions
- Shell & Homebrew6 questions
- System Administration6 questions
- Raspberry Pi6 questions
questions
71 · 3 sectionsHow does the NTFS permission model differ from Unix rwx mode bits, and what does a single access control entry (ACE) contain?
basics
~20 sNTFS attaches a security descriptor with an ordered list of ACEs to every file, so any number of users and groups can each be allowed or denied specific rights. Unix mode bits offer only three fixed slots of read/write/execute.
In the Win32 API, what is a HANDLE, which kernel component manages the objects behind handles, and how does a handle differ from a Unix file descriptor?
basics
~20 sA Windows HANDLE is an opaque, per-process entry in that process's handle table referring to an object created by the NT object manager — a file, event, mutex, process, thread or registry key. A Unix file descriptor is a small integer naming a much narrower set of objects.
In Windows, what is the registry, and how do the HKLM and HKCU root keys differ in scope and in where each is physically stored?
basics
~10 sThe Windows registry is the OS's hierarchical configuration database. HKLM holds machine-wide settings backed by hive files in %SystemRoot%\System32\config; HKCU holds the currently logged-on user's settings, backed by NTUSER.DAT inside that user's profile folder.
Describe the layering of Windows NT: what runs in user mode, what runs in kernel mode, and what do the executive, the kernel layer, and the HAL each do?
basics
~20 sWindows NT layers user mode — applications, subsystem DLLs such as kernel32.dll, and ntdll.dll — over kernel mode, where ntoskrnl.exe holds the executive managers (I/O, memory, process, security), the kernel layer that schedules and dispatches interrupts, plus drivers and the HAL.
On a Windows server, running a .ps1 file fails with "running scripts is disabled on this system". What is PowerShell's execution policy doing, and why is it not treated as a security boundary?
basics
~20 sPowerShell's execution policy is refusing to load the script file — Windows clients default to Restricted, servers to RemoteSigned. It guards against accidentally running an untrusted file, not against a determined user: anyone who can start PowerShell can bypass it.
On macOS, what is the difference between a Launch Agent and a Launch Daemon, and how does that choice change what the job is able to do?
basics
~20 sA Launch Daemon runs in the system domain from boot, normally as root, with no login session and no access to a user's screen. A Launch Agent runs inside a logged-in user's session, as that user, and can reach the GUI.
On macOS, an app downloaded through a web browser is blocked on first launch, but the identical file fetched with curl opens immediately. What mechanism explains the difference?
basics
~20 sThe browser tags its download with the com.apple.quarantine extended attribute; curl does not. Gatekeeper only evaluates quarantined files, so the tagged copy is checked for a valid signature and notarization on first launch while the untagged copy simply runs.
On a Mac formatted with APFS, why do several volumes on the same startup disk each report roughly the same amount of free space, and what is the relationship between an APFS container and the volumes inside it?
basics
~20 sAn APFS container owns all the blocks of its partition, and every volume inside it allocates from that one shared free pool. Volumes therefore have no fixed size, and each reports the container's remaining space as its own available space.
On an Apple Silicon Mac, Homebrew installs under /opt/homebrew instead of the /usr/local prefix it uses on Intel Macs. Why does that split exist, and what has to be configured before the shell finds brew-installed commands?
basics
~20 sHomebrew uses a separate /opt/homebrew prefix on Apple Silicon so an arm64 installation can coexist with an Intel one under /usr/local and so bottles are built for a known default prefix. That directory is not on the default PATH, so brew shellenv must add it.
macOS runs the XNU kernel. What does it mean that XNU is a hybrid kernel, and how is that different from monolithic Linux?
basics
~20 sXNU combines a Mach core providing tasks, threads, port-based IPC and virtual memory with a BSD layer providing POSIX syscalls, processes, VFS and the network stack, plus IOKit for drivers. All of it runs in one kernel address space, so it is hybrid in structure but monolithic in performance.
Why can't you wire a 5 V sensor output straight to a Raspberry Pi GPIO pin, and what do you put in between?
basics
~20 sRaspberry Pi GPIO pins run 3.3 V logic and are not 5 V tolerant, so 5 V on an input can damage the pin or the SoC. Put a level shifter or a resistor divider in between.
Raspberry Pis deployed as always-on devices frequently end up with a corrupted or worn-out microSD card. Why does that happen, and how would you design a deployment to avoid it?
basics
~20 sConsumer microSD cards have limited write endurance and simple controllers, so constant small writes from logs, databases and swap wear them out, while power loss mid-write can corrupt the card's internal mapping. Cut the write rate, or move the root filesystem off the card entirely.
A Raspberry Pi running a camera and a USB disk reboots at random and the disk keeps dropping out, with nothing in the application logs. How do you check whether power is the cause?
basics
~20 sRead the firmware's throttle flags with vcgencmd get_throttled and check the kernel log for under-voltage messages. The bitmask separates a current problem from one that has occurred since boot, and distinguishes low voltage from thermal throttling.
On a current Raspberry Pi OS release, how does a userspace program obtain a GPIO line, and why is the older /sys/class/gpio interface discouraged?
basics
~20 sLinux now exposes GPIO as character devices at /dev/gpiochipN, and a program requests specific lines through ioctls, usually via libgpiod. The kernel releases a line when the requesting file descriptor closes. The older /sys/class/gpio export interface is deprecated and leaves lines stranded.
When would you argue against shipping a product on a consumer Raspberry Pi board, and what would you move to instead?
basics
~20 sArgue against it when the environment, timing or reliability requirements exceed a consumer board: wide ambient temperature range, hard real-time deadlines, uncorrected memory errors, or a mechanical socket that must survive vibration. Move to a Compute Module with eMMC, an industrial SBC, or a microcontroller.