Record firmware versions, boot mode and Secure Boot state across the lab

short · 35 min · Objective 1.3

Task

Build a firmware and driver inventory for every machine in your lab: firmware vendor and version, whether the machine boots in UEFI or legacy mode, whether Secure Boot is on, and the version of one important driver. This is the record a firmware update starts from, and the one that tells you afterwards whether the update actually applied.

Steps

  1. On Linux machines, save dmidecode -t bios to lab/firmware/<host>-bios.txt, and record whether /sys/firmware/efi exists and the output of mokutil --sb-state.
  2. On win-srv, save Get-CimInstance Win32_BIOS | Format-List to lab/firmware/win-srv-bios.txt, and record the output of Confirm-SecureBootUEFI and the BIOS mode shown by msinfo32.
  3. For each machine, record the network adapter's driver and version: ethtool -i <interface> on Linux, Get-NetAdapter | Format-List Name,DriverVersion,DriverProvider on Windows.
  4. Write lab/firmware/inventory.csv with header host,firmware_vendor,firmware_version,boot_mode,secure_boot,nic_driver,nic_driver_version, with boot_mode written UEFI or Legacy as msinfo32 shows it.
  5. For one machine, find the vendor's current firmware version for that model or hypervisor and record in lab/firmware/gap.txt whether an update is available.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

ls lab/firmware/*-bios.txt | wc -l
grep -Eic 'Version|SMBIOSBIOSVersion' lab/firmware/*-bios.txt
awk -F, 'NR>1 && ($4=="UEFI" || $4=="Legacy") {n++} END {print n" host(s) with a boot mode"}' lab/firmware/inventory.csv
awk -F, 'NR>1 && NF>=7 {n++} END {print n" complete row(s)"}' lab/firmware/inventory.csv
grep -c . lab/firmware/gap.txt

Every host has a saved firmware record, a boot mode of UEFI or Legacy and a complete row. Hypervisor guests report the hypervisor's virtual firmware, which is itself worth noticing: in a VM, the firmware is part of the hypervisor and is updated with it.

Notes

A machine installed in UEFI mode will not boot if the firmware is switched to legacy, and the reverse. Recording the mode now is what lets you recognise that fault quickly in the boot failures lesson.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.