skip to content

Windows

Windows as an engineering platform: the NT kernel underneath, the registry and service model, NTFS permissions, PowerShell for automation, and WSL when you need Linux alongside. Enterprise and .NET interviews assume familiarity with all of it.

on this pageshow

explore

questions

30

How does the NTFS permission model differ from Unix rwx mode bits, and what does a single access control entry (ACE) contain?

level: juniorimportance: must knowfreq 70%

answer

  1. security descriptor, not three bits
  2. owner SID, DACL, SACL
  3. one ACE: SID, mask, type, flags
  4. allow and deny, both expressible
  5. inheritance is copied into the child

basics

~20 s

NTFS attaches a security descriptor with an ordered list of ACEs to every file, so any number of users and groups can each be allowed or denied specific rights. Unix mode bits offer only three fixed slots of read/write/execute.

solid answer

~50 s

On Unix a file carries an owner, a group, and nine permission bits — three rwx triples for owner, group and other. NTFS instead stores a **security descriptor** on every file and directory: an owner SID, a **DACL** (the discretionary ACL that decides access), and a **SACL** (auditing plus the integrity label). The DACL is an ordered list of ACEs, and each ACE holds a trustee SID, an access mask of specific rights, an ACE type (allow or deny), and inheritance flags. So NTFS can express "these five groups get different rights, and this one account is explicitly denied" without inventing extra groups. Rights are granular too — reading data, writing data, appending, deleting, reading attributes and changing the ACL are separate bits, not folded into one `w`. Access is evaluated when the handle is opened, and the granted mask is stamped into that handle.

go deeper

for a junior

Be able to say that every NTFS file carries a list of entries naming users or groups with specific rights, and that both Allow and Deny exist — unlike Unix, which has only three fixed rwx slots.

for a middle

Explain the security descriptor's parts and what one ACE holds: trustee SID, access mask, allow/deny type, inheritance flags. Point out granular rights such as append-without-write and delete as their own bit.

for a senior

Show you have debugged this: inherited entries are physically copied into children, so disabling inheritance freezes a divergent copy, and access is checked at handle-open so a DACL edit does not stop a running process.

for a principal

Own the policy angle — decide whether access is granted through group SIDs and inheritance from a small number of roots, or scattered as explicit per-file ACEs, and be able to argue why the second becomes unauditable at scale.

## The two models side by side A Unix file's permissions are nine bits plus an owner UID and a group GID. The kernel picks exactly one triple to apply: if you are the owner it uses the owner triple, otherwise if you are in the file's group it uses the group triple, otherwise it uses other. That is the whole model, and it is beautifully small — but it can only express three distinct opinions about a file. Anything richer forces you to create groups. NTFS takes the opposite trade. Every file and directory carries a *security descriptor*, a variable-length structure with four interesting parts: - the **owner SID** — the security identifier of the principal that owns the object; - a **group SID** — a vestigial field kept for POSIX compatibility, effectively unused by Windows itself; - the **DACL** (discretionary access control list) — the ordered list of ACEs that decides who may do what; - the **SACL** (system access control list) — which access attempts get audited, and the object's mandatory integrity label. A SID is not a small integer like a UID; it is a variable-length identifier such as `S-1-5-21-<domain>-<rid>` for a domain or local account, or a well-known constant such as `S-1-5-18` for LocalSystem. That matters practically: SIDs are unique across machines and domains, so an ACL copied to another machine still names the same principal, whereas a UID means whatever the target machine's passwd database says it means. ## Inside one ACE An access control entry is four things: 1. **Type** — ACCESS_ALLOWED or ACCESS_DENIED (there are audit ACE types too, but those live in the SACL). 2. **Trustee SID** — the user, group, or well-known principal the entry is about. 3. **Access mask** — a 32-bit set of rights. For files these include object-specific bits such as `FILE_READ_DATA`, `FILE_WRITE_DATA`, `FILE_APPEND_DATA`, `FILE_EXECUTE`, `FILE_READ_ATTRIBUTES` and `FILE_DELETE_CHILD`, plus standard rights that every securable object has: `DELETE`, `READ_CONTROL` (read the security descriptor), `WRITE_DAC` (change the DACL) and `WRITE_OWNER`. 4. **Flags** — including the inheritance flags `OBJECT_INHERIT_ACE`, `CONTAINER_INHERIT_ACE`, `INHERIT_ONLY_ACE` and `NO_PROPAGATE_INHERIT_ACE`, and the `INHERITED_ACE` flag marking an entry that came from a parent. The familiar names in the GUI — Full control, Modify, Read & execute — are just conventional bundles of those bits. `icacls` prints them as `(F)`, `(M)`, `(RX)`, with inheritance shown as `(OI)` object inherit, `(CI)` container inherit, `(IO)` inherit only, and a leading `(I)` for an inherited entry. ## Granularity that Unix folds together Several distinctions have no `rwx` equivalent: - **Write versus append.** `FILE_WRITE_DATA` and `FILE_APPEND_DATA` are separate bits, so you can grant a log writer append-only access. - **Delete.** On Unix, removing a name needs write permission on the *directory*; the file's own bits are irrelevant. On NTFS a caller needs `DELETE` on the file itself, or `FILE_DELETE_CHILD` on the parent — two independent paths to the same outcome. - **Reading the ACL versus reading the data.** `READ_CONTROL` and `FILE_READ_DATA` are different rights. - **Deny.** Unix has no way to say "everyone in Engineering except Bob"; an NTFS DACL says it with one deny ACE. ## Inheritance is a copy, not a lookup This is the piece people get wrong. When a file is created inside a directory, the inheritable ACEs from the parent are *copied into the new file's own DACL* and tagged `INHERITED_ACE`. The kernel does not walk up the tree at access time. Changing a parent folder therefore triggers a re-propagation pass down the tree; and a child whose inheritance has been disabled keeps whatever converted copies it had at that moment, permanently diverging from its parent. ``` C:\data\report.txt BUILTIN\Administrators:(I)(F) CONTOSO\alice:(F) ``` Here the `(I)` entry came from `C:\data`; the `alice` entry was set explicitly on the file. ## When the check happens Windows performs the access check once, when a handle is opened, against the *desired access* mask the caller requested. The granted mask is recorded in the handle. Tightening a DACL afterwards does not revoke access through handles that are already open — the process keeps reading until it closes the handle. That surprises people who expect permission changes to bite immediately. ## What interviewers are testing Not the flag letters. They want to hear that you know NTFS security is a list, not a triple; that entries name SIDs and carry both allow and deny; that inheritance is materialised into the child; and that the richness is exactly why Windows permissions are easier to get subtly wrong than `chmod 640`.

  • On Unix, deleting a file depends on write permission on the directory. What governs deletion on NTFS?
    Either right works: the `DELETE` standard right on the file itself, or `FILE_DELETE_CHILD` on the parent directory. That is why a user can sometimes delete a file they cannot open for writing, and why removing `DELETE` from a file is not enough if the parent grants delete-child.
  • If you tighten a file's DACL while a process already has the file open, does that process immediately lose access?
    No. Windows evaluates the DACL once, when the handle is opened, and stamps the granted access into the handle. The running process keeps that access until it closes the handle and tries to reopen. To cut someone off now, you have to terminate the process or break the session, not just edit the ACL.
  • What does the SACL do, and why is it usually empty?
    The SACL holds audit ACEs — which principals and which access attempts generate security-log events — plus the object's mandatory integrity label. It is usually empty because auditing every file access is expensive and noisy; teams enable it selectively on sensitive directories, typically through audit policy rather than per-file edits.

saying these in an interview costs you the question

  • Calls NTFS permissions just rwx bits with longer names
  • Thinks the descriptor's group SID works like a Unix primary group
  • Assumes tightening a DACL cuts off already-open handles
  • Cannot say what a single ACE actually contains
  • Believes inheritance is resolved by walking up at access time

context

open as a page

In the Win32 API, what is a HANDLE, which kernel component manages the objects behind handles, and how does a handle differ from a Unix file descriptor?

level: juniorimportance: must knowfreq 58%

basics

~20 s

A Windows HANDLE is an opaque, per-process entry in that process's handle table referring to an object created by the NT object manager — a file, event, mutex, process, thread or registry key. A Unix file descriptor is a small integer naming a much narrower set of objects.

open as a page

In Windows, what is the registry, and how do the HKLM and HKCU root keys differ in scope and in where each is physically stored?

level: juniorimportance: must knowfreq 76%

basics

~10 s

The Windows registry is the OS's hierarchical configuration database. HKLM holds machine-wide settings backed by hive files in %SystemRoot%\System32\config; HKCU holds the currently logged-on user's settings, backed by NTUSER.DAT inside that user's profile folder.

open as a page

Describe the layering of Windows NT: what runs in user mode, what runs in kernel mode, and what do the executive, the kernel layer, and the HAL each do?

level: middleimportance: must knowfreq 62%

basics

~20 s

Windows NT layers user mode — applications, subsystem DLLs such as kernel32.dll, and ntdll.dll — over kernel mode, where ntoskrnl.exe holds the executive managers (I/O, memory, process, security), the kernel layer that schedules and dispatches interrupts, plus drivers and the HAL.

open as a page

On a Windows server, running a .ps1 file fails with "running scripts is disabled on this system". What is PowerShell's execution policy doing, and why is it not treated as a security boundary?

level: middleimportance: must knowfreq 70%

basics

~20 s

PowerShell's execution policy is refusing to load the script file — Windows clients default to Restricted, servers to RemoteSigned. It guards against accidentally running an untrusted file, not against a determined user: anyone who can start PowerShell can bypass it.

open as a page

Win32 has no fork(): how does CreateProcess differ from the Unix fork/exec model, and what does that change for code ported between the two?

level: middleimportance: must knowfreq 70%

basics

~20 s

CreateProcess builds a new process from an executable image in one call, inheriting only handles that were explicitly marked inheritable. Unix fork first duplicates the caller's address space, so copy-on-write tricks and pre-fork server designs have no direct Win32 equivalent.

open as a page

On Windows, how do a process priority class and a thread's relative priority combine into what the scheduler runs, and what is priority boosting for?

level: middleimportance: must knowfreq 55%

basics

~20 s

Windows ranks threads on 32 priority levels. The process priority class sets a base, the thread's relative priority shifts it, and the scheduler always runs the highest-priority ready thread, preempting lower ones. Temporary boosts lift threads in the dynamic range 1-15 so waiters and starved threads make progress.

open as a page

In the Windows Service Control Manager, how do the Automatic, Automatic (Delayed Start), Manual and Disabled start types differ, and what problem does delayed start solve?

level: middleimportance: must knowfreq 68%

basics

~20 s

Automatic starts a service during boot, Manual only when something requests it, and Disabled blocks starting at all. Automatic (Delayed Start) still starts unattended but after the automatic wave, at lowered priority, so it stops slow services from delaying logon.

open as a page

WSL1 and WSL2 are both called "Windows Subsystem for Linux", but they are architecturally different. Explain how each one actually runs Linux code on Windows, and what that difference changes in practice.

level: middleimportance: must knowfreq 80%

basics

~20 s

WSL1 has no Linux kernel: an NT kernel driver translates Linux system calls, and Linux binaries run as pico processes. WSL2 boots a real Microsoft-built Linux kernel in a lightweight Hyper-V virtual machine, giving full syscall fidelity.

open as a page

Why is Windows server administration normally done in PowerShell rather than through the GUI or cmd.exe?

level: juniorimportance: should knowfreq 62%

basics

~20 s

PowerShell is the management surface Windows itself exposes: server roles ship PowerShell modules, Server Core has no GUI, and a command is repeatable, reviewable and runnable against a whole fleet. GUI clicks and cmd.exe text tools are neither.

open as a page

Inside WSL, an SSH private key stored under /mnt/c/Users/... always reports mode 0777, `chmod 600` does not stick, and ssh refuses to use the key. Why does the permission change not persist, and how do you resolve it?

level: middleimportance: should knowfreq 45%

basics

~20 s

Windows drives are mounted with DrvFs, which by default has nowhere to store Linux mode bits and synthesizes them from mount options, so chmod cannot persist. Either enable the metadata mount option in /etc/wsl.conf, or keep the key in the Linux filesystem.

open as a page

A Windows user's group has an inherited Deny on a folder, but the user has an explicit Allow set directly on a file inside it. Can the user open the file, and how does the access check decide?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Usually yes. Windows walks the DACL in stored order, and canonical order puts explicit entries ahead of inherited ones, so the explicit Allow grants the requested rights before the inherited Deny is ever reached. Deny only wins over Allow within the same tier.

open as a page

An account in the local Administrators group runs a script that writes into C:\Program Files and gets Access Denied. Why, and what changes when the same script is started with 'Run as administrator'?

level: seniorimportance: should knowfreq 55%

basics

~20 s

User Account Control gives an administrator two tokens at logon. Ordinary processes get the filtered one, where the Administrators SID is deny-only and the integrity level is Medium, so ACEs granting Administrators do not apply. Elevation starts a new process with the full token.

open as a page

Why do Windows applications enter the kernel through stubs in ntdll.dll instead of issuing the syscall instruction themselves, and what does that imply about Windows system call numbers?

level: seniorimportance: should knowfreq 40%

basics

~20 s

On Windows the supported contract is the Win32 API and the native routines ntdll.dll exports, not the instruction-level interface. Microsoft renumbers system services freely between builds, so ntdll.dll is the only stable syscall boundary and hardcoded service numbers break on the next update.

open as a page

An Invoke-Command script against a remote Windows server fails with access denied when it reaches a file share, though the same code works when run locally on that server. What is happening in PowerShell remoting, and what are your options?

level: seniorimportance: should knowfreq 52%

basics

~20 s

This is the double-hop problem: PowerShell remoting authenticates you to the target server but does not delegate your credentials onward, so the target reaches the share as its own machine identity and is refused. Fixes are constrained delegation, CredSSP, or supplying a credential on the remote side.

open as a page

A Windows build agent must guarantee that when a build ends, every process it spawned is gone — including grandchildren. Why isn't terminating the top process enough, and what does the OS give you?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Terminating a process on Windows kills only that process; there is no supervisory link that carries the kill to descendants. A job object does: assign the top process to a job, set JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE, and every process in the job — children included — dies when the job handle closes.

open as a page

What goes wrong when a callback on the Windows default thread pool blocks for several seconds, and what does the thread pool API offer for genuinely long-running work?

level: seniorimportance: should knowfreq 33%

basics

~20 s

A blocked callback occupies a shared worker thread. Because the pool adds threads gradually rather than instantly, other queued work — timers, waits and I/O completions from anywhere in the process — is delayed behind it. Call CallbackMayRunLong, use a private pool, or run long work on a dedicated thread.

open as a page

A Windows service must run unattended and also reach a file share on another server. How do LocalSystem, LocalService, NetworkService and a virtual account differ, and how would you choose between them?

level: seniorimportance: should knowfreq 56%

basics

~20 s

LocalSystem is fully privileged locally and authenticates on the network as the computer account. NetworkService has low local privilege but the same computer-account network identity. LocalService is low privilege and anonymous on the network. A virtual account gives a per-service identity with the computer account's network access and no password to manage.

open as a page

On Windows, why is write access for a non-administrator to a service's key under HKLM\SYSTEM\CurrentControlSet\Services treated as a privilege escalation, and what related weaknesses are checked alongside it?

level: seniorimportance: should knowfreq 36%

basics

~20 s

That key defines which binary the service runs and which account runs it. Anyone who can write it can point ImagePath at their own executable and have the Service Control Manager launch it as LocalSystem at the next start, turning a registry permission into full machine control.

open as a page

A Windows service fails to start with "Error 1053: The service did not respond to the start or control request in a timely fashion." What does the Service Control Manager expect from a service process, and where do recovery actions fit in?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Error 1053 means the process never reported back to the Service Control Manager in time. A service must connect to the SCM and report its status within roughly 30 seconds, reporting start-pending with a wait hint if initialisation is slow — an ordinary console program run as a service always fails this way.

open as a page

A developer using WSL2 keeps a Git repository under /mnt/c/Users/... and reports that `git status` and dependency installs take many times longer than the same repository in their Linux home directory. What is causing the gap, and what do you tell them to do?

level: seniorimportance: should knowfreq 62%

basics

~20 s

Under WSL2, /mnt/c is served over the 9P protocol across the virtual-machine boundary, so every file operation is a round trip to Windows. Metadata-heavy workloads pay that latency thousands of times. Move the project into the Linux filesystem.

open as a page

How is a WSL2 distribution attached to the network by default, and why can a browser on Windows reach a server listening on localhost inside WSL2 while a process inside WSL2 cannot reach a Windows service the same way?

level: seniorimportance: should knowfreq 50%

basics

~20 s

By default the WSL2 utility VM sits behind NAT on its own virtual adapter with its own IP. Windows-to-Linux works because WSL relays Windows localhost connections into the VM; there is no relay in the other direction, so localhost inside the VM means the VM.

open as a page

On Windows, how would you decide whether new functionality — say, intercepting or instrumenting file I/O — belongs in a kernel-mode driver or a user-mode component, and what does choosing kernel mode commit you to?

level: principalimportance: should knowfreq 30%

basics

~20 s

Default to user mode and move to kernel mode only when you must sit in the I/O path or observe what no user-mode interface exposes. Kernel mode means a bug bugchecks the whole machine, and it commits you to IRQL and pool discipline, code signing, and lockstep servicing with the OS.

open as a page

When is hard-pinning threads with SetThreadAffinityMask on Windows justified, and what does it cost compared with leaving placement to the scheduler?

level: principalimportance: should knowfreq 28%

basics

~20 s

A hard affinity mask forbids the scheduler from using any other processor, so a pinned thread waits while cores sit idle and the mask encodes today's topology into the binary. Justify it only with measurements, and prefer softer expressions of preference such as an ideal processor or CPU sets.

open as a page

Windows registry values are typed. What is the difference between REG_SZ and REG_EXPAND_SZ, and what must code reading the latter do differently?

level: juniorimportance: nice to knowfreq 34%

basics

~20 s

REG_SZ is a plain string stored literally. REG_EXPAND_SZ is a string that still contains unexpanded environment-variable references such as %SystemRoot%, so the reader must expand it before use — otherwise it gets a path that does not exist.

open as a page

From a bash shell inside WSL you can type `notepad.exe` and a Windows program opens, and you can pipe Linux output into it. What makes that work, and what goes wrong when you pass a Linux path such as /home/me/report.txt to a Windows program?

level: juniorimportance: nice to knowfreq 35%

basics

~20 s

WSL registers Windows executables with the Linux kernel's binfmt_misc mechanism, so exec'ing a .exe hands it to an interop service that starts it on the Windows side with stdio piped back. Windows programs cannot understand Linux paths, so convert them with wslpath.

open as a page

What is an NTFS alternate data stream, and how does Windows use one to mark files downloaded from the internet?

level: middleimportance: nice to knowfreq 38%

basics

~20 s

NTFS stores a file as a set of named data streams, not one blob. Content beyond the default unnamed stream is an alternate data stream, addressed as file.txt:name. Windows writes one called Zone.Identifier to record that a file came from the internet.

open as a page

What is a Windows fiber, how does it differ from a thread, and why do so few applications use fibers?

level: middleimportance: nice to knowfreq 20%

basics

~20 s

A fiber is a user-mode execution context — its own stack and register state — that the application schedules itself by calling SwitchToFiber. The kernel never sees it and schedules only the host thread, so fibers are cooperative, give no parallelism on their own, and one blocking call stalls every fiber on that thread.

open as a page

On Windows, the window manager and GDI run in kernel mode inside win32k.sys. Why were they put there, and what does that design cost?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

Windows NT 4.0 moved the window manager and GDI out of the user-mode subsystem server into kernel mode as win32k.sys, removing a process-boundary crossing from every drawing and message call. The cost is a very large kernel attack surface and graphics faults that can bugcheck the machine.

open as a page