Basic System Security

Learn Basic System Security. This module covers Configuring the UFW Firewall, Auditing User Logins, Secure Shared Memory on Tmpfs, Understanding Sudoers Configuration, Checking Listening Ports for Security Audit. You will master these essential Linux skills through hands-on labs and real-world challenges.

DevOps EngineerLinuxDevOps

Introduction

Basic Linux hardening is less about applying one magic setting and more about understanding exposure, activity, privileges, and enforcement as separate layers. This hands-on course gives you a repeatable way to inspect those layers and make controlled security changes while verifying their effects.

You will audit listening services and login records, enable UFW with lab-safe rules, block direct execution from shared memory, and grant sudo access through syntax-checked configuration. The final mission combines these tasks into a documented network, user-activity, filesystem, and privilege review.

What You Will Learn

  • Enumerate listening TCP sockets and their owning processes with ss -lntp
  • Trace a non-standard listening port to its user, PID, and launch command
  • Configure, enable, inspect, and connectivity-test a UFW firewall policy
  • Compare active sessions, login history, and reboot history with w and last
  • Remount /dev/shm with noexec and verify that direct script execution is blocked
  • Assess and grant sudo privileges safely with visudo, then verify the result
  • Save port, session, and login evidence as files during a hardening audit

Who This Course Is For

This intermediate course is for Linux administrators, DevOps and security learners, support engineers, and developers who want practical experience with foundational host-security controls. It is suited to learners who need to audit network exposure, review account activity, harden a writable filesystem, or understand delegated administration.

Prerequisites: Basic Linux terminal, process, permission, networking, and redirection skills, plus comfort using sudo and a terminal text editor.

Learning environment: A privileged LabEx Linux terminal with prepared web and test services, UFW, tmpfs-backed /dev/shm, login records, and training users for sudoers exercises.

Frequently Asked Questions

Does this course build a production-ready deny-by-default firewall?

No. To avoid disconnecting the online lab, the exercises deliberately set UFW's default incoming policy to allow and add explicit rules for port 8080 or SSH port 22. The course teaches configuration and verification mechanics, while clearly identifying deny-by-default as the usual production baseline.

Is the /dev/shm hardening persistent after a reboot?

No. You apply noexec with a live mount -o remount command and verify its immediate effect. The course does not edit /etc/fstab or another persistent mount configuration.

Do the sudoers exercises follow least privilege?

They demonstrate safe editing with visudo, but intentionally grant the training users full ALL command access. In a real environment, you would normally narrow the allowed commands and scope to the user's actual responsibilities.

Teacher

labby
Labby
Labby is the LabEx teacher.