Introduction
Welcome to the course
()
Hardening systems for compliance and threat reduction
()
Introducing CIS Benchmarks and DISA STIGs
()
Setting up your practice environment
()
1. Filesystem and Hardware Security
Partition layout and mount options
()
Setting a bootloader password
()
Protecting data with disk encryption
()
Surveying file permissions and discretionary controls
()
Establishing file integrity monitoring with AIDE
()
Restricting USB device access
()
2. Mandatory Access Controls and SELinux
Mandatory access control overview
()
Understanding SELinux modes, policies, and contexts
()
Managing SELinux booleans
()
Troubleshooting denials with audit2why and audit2allow
()
3. PAM and Privilege
Understanding Pluggable Authentication Modules (PAM)
()
Exploring PAM configuration
()
Configuring PAM with authselect
()
Enforcing password quality
()
Using sudo
()
4. SSH Security
Hardening SSH
()
Configuring authentication controls
()
Hardening other features of SSH
()
Applying system-wide crypto policies
()
Controlling access
()
5. Firewall
Understanding firewalld and firewall-cmd
()
Managing zones and interfaces
()
Defining and applying services
()
Writing rich rules for complex scenarios
()
Persisting and auditing the firewall configuration
()
6. Patch Management
Planning patching cadence and coverage
()
Understanding DNF and subscription management basics
()
Applying security-only updates and CVE-targeted patches
()
Exploring automatic patching, kernel updates, and reboots
()
7. Audit Logging
Understanding auditd
()
Writing audit rules for files and syscalls
()
Querying logs with ausearch and aureport
()
Configuring log retention and rotation
()
8. Auditing and Remediating Systems
Exploring OpenSCAP and scap-security-guide
()
Running a compliance scan and reading the results
()
Performing manual remediation
()
Performing automated remediation
()
Making exceptions and customizing profiles
()