QuestionQ304

Tools/Systems/Programs

During a forensic reconstruction of an Intel-based Mac’s startup in San Jose, California, examiners need to identify the stage that verifies the macOS bootloader before the operating system begins. Which component carries out this verification?

  • A iBoot
  • B UEFI firmware
  • C Boot ROM
  • D boot.efi
Explanation

On an Intel-based Mac with Apple T2 secure boot, the chain of trust continues on the Intel CPU, where the UEFI firmware evaluates the signature of the macOS bootloader (boot.efi) before macOS starts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!