Linux hardening is strongest when it begins with observed host state and ends with both an allowed-path and denied-path test. This challenge-only course applies that method across 20 focused scenarios involving network exposure, local permissions, service identity, privileged automation, secrets, scripts, and application policy.
You will inspect sockets, processes, /proc, ownership, modes, sudoers, Cron definitions, HTTP responses, and helper scripts before making narrowly scoped changes. Every remediation must preserve the intended site, health check, service write path, approved command, or backup workflow while closing the unsafe path.
What You Will Learn
- Classify live TCP bindings, restrict an admin listener to loopback, and remove an unnecessary legacy port
- Disable directory indexes, relocate a public backup archive, close diagnostics, and remove debug or incident-only responses
- Tighten secret files, environment files, upload directories, and application logs while preserving intended user or group access
- Replace broad sudo authority with one command-specific rule and harden a root-run Cron execution directory against untrusted writes
- Move hardcoded and process-environment credentials into protected files and verify secrets disappear from scripts or
/procexposure - Run a local service as its dedicated non-root account and retain its health and log-append behavior
- Restore token-gated application policy by removing temporary allow-all or bypass settings and test both denied and authorized requests
- Pin script command resolution to trusted system paths and reject normalized backup inputs that escape the approved data directory
Who This Course Is For
This course is for DevSecOps practitioners, Linux administrators, and platform learners who want to harden existing host services through evidence-driven challenges.
Prerequisites: Confident Linux terminal use, ss, process inspection, users and groups, ownership and permission modes, sudoers and visudo, Cron, shell scripts, environment files, HTTP testing, and basic path normalization; this is not a beginner walkthrough.
Learning environment: A browser-accessible Linux host with sudo, prepared local users, services, scripts, files, and loopback HTTP endpoints; each challenge strictly limits the paths, ports, identities, and behavior you may change.
Frequently Asked Questions
Is this a guided Linux fundamentals course?
No. Each challenge supplies a current situation, strict scope, acceptance criteria, and hints, but you must inspect live evidence, choose the smallest safe fix, restart through the provided path, and test the result.
Do the secret challenges use Vault or another production secret manager?
No. They focus on removing literals and process-environment exposure by using prepared files with modes such as 600 or 640. Rotation, encryption, central secret stores, and credential issuance are outside scope.
Does the course configure a host firewall, SELinux, or AppArmor?
No. Network exercises change application listeners and routes, while access exercises use Unix permissions, service users, sudoers, configuration, and script validation. Kernel MAC policy and firewall administration are not covered.
How does the course prove a fix did not break operations?
Acceptance criteria pair the new denial with preserved behavior—for example, an admin route rejects missing tokens but accepts the approved token, an unrelated user cannot read a log while the service can append, or an outside backup path fails while an in-bounds backup succeeds.





