Posts

Showing posts with the label Storage

Journaling File Systems: Crash Consistency and What the Journal Tells Investigators

Writing a file is not one operation. The data blocks are written, the allocation map is updated, the directory entry is created, and timestamps are changed — and a power loss between any two of those leaves the file system inconsistent. Journaling solves this by recording what is about to happen before doing it. The problem journaling solves An interrupted write can leave blocks marked as in use that belong to no file, a directory entry pointing at nothing, or a file whose length does not match its allocated blocks. None of these are detectable without checking, which is why non-journaling file systems require a full consistency scan after an unclean shutdown. That scan walks the entire file system, and its duration scales with size. On a multi-terabyte volume it takes hours — hours during which the system is unavailable, which is the operational argument for journaling quite apart from correctness. How it works Before modifying the file system, the intended changes a...

SSD Sanitization and Cryptographic Erase: Why Overwriting Fails

Overwriting every addressable sector is a sound way to sanitize a magnetic hard drive and an unreliable way to sanitize a solid state drive. The reason is architectural, not a matter of doing more passes, and understanding it is what separates a correct answer from a confident wrong one. Why overwriting does not reach the data Flash memory cells wear out after a finite number of write cycles, so an SSD controller distributes writes across the whole device to extend its life. The logical block address the operating system writes to is mapped by the controller to whatever physical cell it chooses, and that mapping changes constantly. So when software overwrites logical block 500, the controller writes the new data to a fresh physical cell and marks the old one invalid. The original data is still physically present, just no longer reachable through the normal interface. Over-provisioning compounds this. Drives contain more flash than they advertise — commonly seven to twenty-eig...

JBOD Explained: Just a Bunch of Disks vs RAID for Server+ and A+

JBOD stands for Just a Bunch of Disks — occasionally written as Just a Bunch of Drives. The name is almost aggressively plain, and it describes exactly what it is: several physical drives attached to a system without being combined into a RAID array. JBOD gives you capacity and flexibility. It gives you no redundancy and no performance gain. Everything about it follows from that trade. The Two Things People Mean by JBOD The term gets used loosely, and exams distinguish between two arrangements. Independent disks. Each drive is presented to the operating system separately, with its own volume and drive letter. Four 4 TB disks become four 4 TB volumes. This is the literal reading of the name. Spanning, or concatenation. Drives are joined end to end into one large logical volume. Four 4 TB disks become a single 16 TB volume. Data fills the first disk, then continues onto the second, and so on. This is sometimes called BIG or SPAN. The distinction matters for failure behavi...

Drive Endurance Explained: AFR, TBW and DWPD for the Server+ Exam

Vendors publish several reliability figures for storage, and they measure different things. Choosing a drive for a workload means reading them correctly — and the most common mistake is treating MTTF as a lifespan. For the general definitions of MTBF, MTTF and availability, see the companion article linked at the end. This one is about the storage-specific ratings. MTTF and AFR MTTF — mean time to failure — applies to items that are replaced rather than repaired, which is what a drive is. A figure of 1,200,000 hours does not mean the drive lasts 137 years. It is a fleet statistic describing the failure rate during the drive's useful life. Across 1,000 such drives you would expect roughly one failure every 1,200 hours — about once every seven weeks. AFR — annualised failure rate — expresses the same thing more usefully: the percentage of drives expected to fail in a year. Convert with AFR ≈ 8,760 ÷ MTTF, so 1,200,000 hours is about 0.73%. AFR is the figure to plan with. In a...

FAT32 Explained: The 4GB Limit, exFAT and NTFS for the A+ Exam

FAT32 is the file system that refuses to die. Microsoft introduced it in 1996 with Windows 95 OSR2, replaced it with NTFS years ago, and it is still the default on USB sticks, SD cards, and camera storage worldwide — because it is the one format that everything can read. FAT32's limitations are severe and its compatibility is universal. Those two facts explain every decision anyone makes about it. The Limits You Must Know These are the most tested facts on the topic, and they are worth memorizing exactly. Maximum file size: 4 GB — strictly, 4 GB minus 1 byte. This is the one that bites people in practice, because a single video file, disk image, or large backup exceeds it and the copy fails partway through. Maximum volume size: 2 TB with standard 512-byte sectors. Windows will only format up to 32 GB through its own GUI, though it will happily read and use larger FAT32 volumes formatted elsewhere. That 32 GB figure is a Microsoft restriction, not a FAT32 one — a disti...

exFAT vs FAT32 vs NTFS: Choosing a File System for Removable Media

exFAT was created to solve one specific problem: FAT32 cannot store a file larger than 4 GB, and by the time high-definition video and large disk images became ordinary, that limit had become intolerable on removable media. The obvious alternative was NTFS, but NTFS carries permissions, journaling and Windows-specific metadata that make it a poor fit for a memory card moving between a camera, a phone and a laptop. exFAT is the middle option: modern capacity limits, minimal overhead, broad compatibility. The Three, Compared FAT32 — maximum file size 4 GB minus one byte, maximum volume size 2 TB in practice (32 GB when formatting through the Windows GUI). Universally readable by essentially every device ever made. No permissions, no journaling, no encryption. Covered further in FAT32 . exFAT — file and volume limits so large they are irrelevant in practice (128 PB). Supported by Windows, macOS, modern Linux, Android and most cameras. Larger cluster sizes suited to bi...

M.2 SSD Explained: Keys, NVMe vs SATA and Sizes for the A+ Exam

M.2 is a form factor, not a protocol. That single sentence resolves most of the confusion around these drives, and it is what the A+ exam is really testing. An M.2 slot is a physical connector on the motherboard. What runs across it may be SATA or NVMe, and the performance difference between the two is large. NVMe versus SATA over M.2 M.2 SATA M.2 NVMe Protocol SATA (AHCI) NVMe over PCIe Speed ceiling about 600 MB/s 3,500 MB/s and far beyond Typical keying B+M (two notches) M only (one notch) Queue depth 1 queue, 32 commands 65,535 queues An M.2 SATA drive is capped at the same 600 MB/s as any other SATA III device, because it is using the SATA protocol — the connector changed, the bus did not. NVMe talks directly over PCIe lanes and skips the translation layer that AHCI imposes, which is why it is several times faster. The deep queue matters more than the headline sequential number. AHCI was designed for spinning disks with one head; NVMe was designed for flash that can ser...

eSATA Explained: External SATA for the CompTIA A+ Exam

eSATA is the external version of the SATA interface. Same protocol, same speeds, different connector — and one design decision that explains almost every exam question about it: the standard eSATA cable carries data only, and no power. It shows up on the A+ exam as a legacy port you need to identify on sight and reason about, rather than something you would specify for a new build today. What makes it different from internal SATA eSATA was designed for cables that get plugged and unplugged, run further, and sit outside a shielded case. That produced four differences from the internal connector. Different keying. The eSATA connector has no L-shaped notch, so it will not mate with an internal SATA port. This is deliberate, and it is the quickest way to tell the two apart in a photograph. Extra shielding. The connector and cable are shielded for use outside the chassis. More insertion cycles. Internal SATA connectors are rated for roughly 50 insertions. eSATA is rated for several...

SATA Explained: Connectors, Speeds and Troubleshooting for the A+ Exam

Image
SATA is one of those topics the A+ exam keeps coming back to, because almost every desktop and laptop you will ever open has a SATA device in it or a slot where one used to be. Serial ATA replaced the old Parallel ATA ribbon cables in the mid-2000s and stayed the default storage interface for two decades. The exam does not ask you to design a storage controller. It asks whether you can identify a connector on sight, quote the speed of a revision, and work out why a drive is not showing up. What SATA actually is SATA is a point-to-point serial interface between a host controller and a single storage device. Two words in that sentence matter. Serial means one bit at a time down a differential pair, rather than sixteen bits in parallel down a ribbon. That sounds slower, and per-wire it is, but serial links can be clocked far higher because you are not fighting to keep sixteen signals in step with each other. Parallel ATA topped out at 133 MB/s. SATA started at 150 and went up from t...