Basic Linux hardening is less about applying one magic setting and more about understanding exposure, activity, privileges, and enforcement as separate layers. This hands-on course gives you a repeatable way to inspect those layers and make controlled security changes while verifying their effects.
You will audit listening services and login records, enable UFW with lab-safe rules, block direct execution from shared memory, and grant sudo access through syntax-checked configuration. The final mission combines these tasks into a documented network, user-activity, filesystem, and privilege review.
What You Will Learn
- Enumerate listening TCP sockets and their owning processes with
ss -lntp - Trace a non-standard listening port to its user, PID, and launch command
- Configure, enable, inspect, and connectivity-test a UFW firewall policy
- Compare active sessions, login history, and reboot history with
wandlast - Remount
/dev/shmwithnoexecand verify that direct script execution is blocked - Assess and grant sudo privileges safely with
visudo, then verify the result - Save port, session, and login evidence as files during a hardening audit
Who This Course Is For
This intermediate course is for Linux administrators, DevOps and security learners, support engineers, and developers who want practical experience with foundational host-security controls. It is suited to learners who need to audit network exposure, review account activity, harden a writable filesystem, or understand delegated administration.
Prerequisites: Basic Linux terminal, process, permission, networking, and redirection skills, plus comfort using sudo and a terminal text editor.
Learning environment: A privileged LabEx Linux terminal with prepared web and test services, UFW, tmpfs-backed /dev/shm, login records, and training users for sudoers exercises.
Frequently Asked Questions
Does this course build a production-ready deny-by-default firewall?
No. To avoid disconnecting the online lab, the exercises deliberately set UFW's default incoming policy to allow and add explicit rules for port 8080 or SSH port 22. The course teaches configuration and verification mechanics, while clearly identifying deny-by-default as the usual production baseline.
Is the /dev/shm hardening persistent after a reboot?
No. You apply noexec with a live mount -o remount command and verify its immediate effect. The course does not edit /etc/fstab or another persistent mount configuration.
Do the sudoers exercises follow least privilege?
They demonstrate safe editing with visudo, but intentionally grant the training users full ALL command access. In a real environment, you would normally narrow the allowed commands and scope to the user's actual responsibilities.





