---
tags:
- linux
- l1
- flashcard-deck
- linux-security
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Linux Hardening](../../../../library/portal/topics.md) | **Domain:** Linux
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
linux-security/0195fe8f4def	linux-security	easy	linux, permissions, system	How to recursively change permissions for all directories except files and for all files except directories?	To change all the directories e.g. to **755** (`drwxr-xr-x`):\n\n```bash\nfind /opt/data -type d -exec chmod 755 {} \;\n```\n\nTo change all the files e.g. to **644** (`-rw-r--r--`):\n\n```bash\nfind /opt/data -type f -exec chmod 644 {} \;\n```\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/014-how-to-recursively-change-permissions-for-all-dire.txt
linux-security/0aff37c3ea5a	linux-security	easy	linux, security, logging, users	How to see a list of who logged in to the system?	Several commands show login history:\n\nCurrent users:\n- who - Currently logged in users\n- w - Logged in users with activity\n- users - Simple list of usernames\n\nLogin history:\n- last - Recent logins from /var/log/wtmp\n- last username - Specific user history\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/400-how-to-see-a-list-of-who-logged-in-to-the-system.txt
linux-security/0c931984d913	linux-security	medium	linux, permissions, users	What does the following permissions mean?:	\n777 - You give the owner, group and other: Execute (1), Write (2) and Read (4); 4+2+1 = 7.\n644 - Owner has Read (4), Write (2), 4+2 = 6; Group and Other have Read (4).\n750 - Owner has x+r+w, Group has Read (4) and Execute (1); 4+1 = 5. Other have no permissions.\n\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/159-what-does-the-following-permissions-mean-777-644-7.txt
linux-security/0df2c620be10	linux-security	easy	audit, linux, system, users	Why do we use `sudo su -` and not just `sudo su`?	`sudo` is in most modern Linux distributions where (but not always) the root user is disabled and has no password set. Therefore you cannot switch to the root user with `su` (you can try). You have to call `sudo` with root privileges: `sudo su`.\n\n`su` just switches the user, providing a normal shell with an environment nearly the same as with the old user.\n\n`su -` invokes a login shell after switching the user. A login shell resets most environment variables, providing a clean base.	projects/knowledge/interview/linux/028-why-do-we-use-codesudo-su-code-and-not-just-codesu.txt
linux-security/0ec2a01cbed7	linux-security	hard	chroot, linux, system, users	What is the main advantage of using `chroot`? When and why do we use it? What is the purpose of the mount dev, proc, sys in a chroot environment?	An advantage of having a chroot environment is the file-system is totally isolated from the physical host. `chroot` has a separate file-system inside the file-system, the difference is its uses a newly created root(/) as its root directory.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/095-what-is-the-main-advantage-of-using-codechrootcode.txt
linux-security/15f3f61120b9	linux-security	medium	linux, permissions, users	Explain what are ACLs. For what use cases would you recommend to use them?	ACL stands for Access Control Lists. We can use ACL to have more granular control over accesses to certain files for certain users specifically. For instance, we can return the ACL of a particular file with the command `getfacl /absolute/file/path` and modify ACLs for a specific file with `setfacl -m`.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/165-explain-what-are-acls-for-what-use-cases-would-you.txt
linux-security/222489455093	linux-security	hard	encryption, linux, system	What is the difference between encryption and hashing?	**Hashing**: Finally, hashing is a form of cryptographic security which differs from **encryption** whereas **encryption** is a two step process used to first encrypt and then decrypt a message, **hashing** condenses a message into an irreversible fixed-length value, or hash.\n\nRemember: LUKS = disk encryption. `cryptsetup luksFormat /dev/sdb1`.	projects/knowledge/interview/linux/112-what-is-the-difference-between-encryption-and-hash.txt
linux-security/228a560407a1	linux-security	medium	encryption, linux, users	Which file stores users passwords? Is it visible for everyone?	`/etc/shadow` file holds the passwords of the users in encrypted format. NO, it is only visible to the `root` user\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/393-which-file-stores-users-passwords-is-it-visible-fo.txt
linux-security/22a625090378	linux-security	medium	linux, security, selinux, mac	SELinux enforcing vs permissive?	Enforcing blocks violations.\n\nPermissive logs AVC denials but allows execution—used for debugging and policy development.\n\nRemember: SELinux: Enforcing, Permissive, Disabled. Check: `getenforce`. "EPD."\n\nGotcha: `setenforce 0` is temporary. Permanent: `/etc/selinux/config`. Disabling breaks compliance.	projects/knowledge/interview/linux/548-selinux-enforcing-vs-permissive.txt
linux-security/2489baf2ac20	linux-security	medium	linux, permissions	How to change the permissions of a file?	Using the `chmod` command.\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/158-how-to-change-the-permissions-of-a-file.txt
linux-security/25c2978c59a3	linux-security	medium	linux, chroot, security, isolation	What is chroot? In what scenarios would you consider using it?	chroot changes the apparent root directory for a process.\n\nHow it works:\n- chroot /newroot /bin/bash\n- Process sees /newroot as /\n- Can't access files outside\n\nUse cases:\n1. System recovery - Boot from live CD, chroot to repair\n2. Build environments - Isolated compilation\n3. Legacy applications - Run with old libraries\n4. Basic isolation - Simple sandboxing\n5.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/364-what-is-chroot-in-what-scenarios-would-you-conside.txt
linux-security/25c86c53bb4f	linux-security	medium	encryption, linux, ssh	How do you create a private key for a CA (certificate authority)?	One way is using openssl this way:\n\n`openssl genrsa -aes256 -out ca-private-key.pem 4096`\n\nRemember: TLS port 443. Chain: Root CA→Intermediate→Server. Let's Encrypt=free, 90-day.	projects/knowledge/interview/linux/246-how-do-you-create-a-private-key-for-a-ca-certifica.txt
linux-security/267c84b9a0bf	linux-security	medium	linux, users	How to switch to another user? How to switch to the root user?	su command.\nUse su - to switch to root\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/271-how-to-switch-to-another-user-how-to-switch-to-the.txt
linux-security/2ec2eccd1de2	linux-security	easy	linux, permissions, security, sticky-bit, filesystem	"How does ""Sticky Bit"" work on a directory?"	The sticky bit restricts file deletion in shared directories to owners only.\n\nHow it works:\n- When set on a directory (not files), only the file owner, directory owner, or root can delete/rename files within\n- Other users with write permission to the directory cannot delete others' files\n- Classic use case: /tmp directory\n\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/531-sticky-bit-directory.txt
linux-security/360ca0895c72	linux-security	hard	audit, linux, ssh, system	What is the difference between `/sbin/nologin`, `/bin/false`, and `/bin/true`?	When `/sbin/nologin` is set as the shell, if user with that shell logs in, they'll get a polite message saying 'This account is currently not available'.\n\n`/bin/false` is just a binary that immediately exits, returning false, when it's called, so when someone who has false as shell logs in, they're immediately logged out when false exits.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/099-what-is-the-difference-between-codesbinnologincode.txt
linux-security/37343de9840c	linux-security	medium	linux, permissions, chmod	What does chmod 755 filename do?	Sets file permissions to rwxr-xr-x (owner can read/write/execute, group and others can read/execute).\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/559-what-does-chmod-755-do.txt
linux-security/3ece6684dc3c	linux-security	easy	linux, users	What is sudo? How do you set it up?	"sudo is a command-line utility in Unix-like operating systems that allows users to run programs with the privileges of another user, usually the superuser (root). It stands for ""superuser do.\n\nThe sudo program is installed by default in almost all Linux distributions. If you need to install sudo in Debian/Ubuntu, use the command apt-get install sudo"\n\nRemember: sudo config: `/etc/sudoers`. ALWAYS edit with `visudo` — validates syntax.\n\nGotcha: Broken sudoers = locked out. visudo prevents by checking before saving.	projects/knowledge/interview/linux/164-what-is-sudo-how-do-you-set-it-up.txt
linux-security/45aed3711484	linux-security	medium	linux, firewall, firewalld, security	What is firewalld daemon responsible for?	firewalld is a dynamic firewall manager for Linux.\n\nResponsibilities:\n- Managing firewall rules\n- Zone-based configuration\n- Runtime and permanent rules\n- D-Bus interface for applications\n\nFeatures:\n- Zones: Different trust levels (public, home, trusted)\n\nRemember: Ubuntu=UFW, RHEL=firewalld. Both=iptables/nftables frontends.	projects/knowledge/interview/linux/368-what-firewalld-daemon-is-responsible-for.txt
linux-security/55299b029b4a	linux-security	medium	linux, permissions, system	Explain the differences among the following umask values: 000, 002, 022, 027, 077, and 277.	Each umask subtracts permissions from defaults (666 files, 777 dirs).\n\n- 000: files=666 (rw-rw-rw-), dirs=777 (rwxrwxrwx) -- no restrictions\n- 002: files=664 (rw-rw-r--), dirs=775 -- others can't write\n- 022: files=644 (rw-r--r--), dirs=755 -- only owner writes (common default)\n- 027: files=640, dirs=750 -- others get nothing\n- 077: files=600, dirs=700 -- only owner has access\n- 277: files=400, dirs=500 -- owner can only read\n\nRemember: umask subtracts from 666(files)/777(dirs). 022→644/755. "What to remove."	projects/knowledge/interview/linux/044-explain-the-differences-among-the-following-umask-.txt
linux-security/586b8aadca3f	linux-security	medium	linux, security, recovery, root	What can you do if you lost/forgot the root password?	Boot into single-user/rescue mode to reset:\n\nGRUB method:\n1. Reboot, edit GRUB entry (press 'e')\n2. Find linux line, append: init=/bin/bash (or single)\n3. Boot (Ctrl+X or F10)\n4. Remount root: mount -o remount,rw /\n5. Reset password: passwd root\n6. Reboot: exec /sbin/init (or reboot -f)\n\nWith systemd:\n- Append: rd.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/398-what-can-you-do-if-you-lostforogt-the-root-passwor.txt
linux-security/58b4fe6dbc69	linux-security	easy	encryption, linux, system	Where is my password stored on Linux/Unix?	"The passwords are not stored anywhere on the system at all. What is stored in `/etc/shadow` are so called hashes of the passwords.\n\nA hash of some text is created by performing a so called one way function on the text (password), thus creating a string to check against. By design it is ""impossible"" (computationally infeasible) to reverse that process.\n"\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/013-where-is-my-password-stored-on-linuxunix.txt
linux-security/5baba54d205e	linux-security	medium	encryption, linux, ssh	How do you create a public key for a CA (certificate authority)?	`openssl req -new -x509 -days 730 -key [private key file name] -sha256 -out ca.pem`\n\nIf using the private key from the previous question then the command would be:\n\n`openssl req -new -x509 -days 730 -key ca-private-key.pem -sha256 -out ca.pem`\n\nRemember: TLS port 443. Chain: Root CA→Intermediate→Server. Let's Encrypt=free, 90-day.	projects/knowledge/interview/linux/247-how-do-you-create-a-public-key-for-a-ca-certificat.txt
linux-security/5ecac569a51c	linux-security	hard	encryption, linux, system, users	Should the root certificate go on the server?	**Self-signed root certificates** need not/should not be included in web server configuration. They serve no purpose (clients will always ignore them) and they incur a slight performance (latency) penalty because they increase the size of the SSL handshake.\n\n\nRemember: TLS port 443. Chain: Root CA→Intermediate→Server. Let's Encrypt=free, 90-day.	projects/knowledge/interview/linux/113-should-the-root-certificate-go-on-the-server.txt
linux-security/5ee48a577910	linux-security	easy	linux, permissions, users	What is the purpose of sticky bit?	Its a bit that only allows the owner or the root user to delete or modify the file.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/162-what-is-the-purpose-of-sticky-bit.txt
linux-security/67dcdf3936be	linux-security	easy	audit, linux, system, users	Running the command as root user. It is a good or bad practices?	Running (everything) as root is bad because:\n\n- **Stupidity**: nothing prevents you from making a careless mistake. If you try to change the system in any potentially harmful way, you need to use sudo, which ensures a pause (while you're entering the password) to ensure that you aren't about to make a mistake.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/010-running-the-command-as-root-user-it-is-a-good-or-b.txt
linux-security/68101f00cd83	linux-security	medium	encryption, linux, users	How do you create users? Where user information is stored?	Command to create users is `useradd` \n\nSyntax:\n`useradd [options] Username`\n\nThere are 2 configuration files, which stores users information\n\n1. `/etc/passwd` - Users information like, username, shell etc is stored in this file \n\n2. `/etc/shadow` - Users password is stored in encrypted format\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/390-how-do-you-create-users-where-user-information-is-.txt
linux-security/683ff58c849e	linux-security	medium	encryption, linux, users	What information is stored in /etc/passwd? explain each field	`/etc/passwd` is a configuration file, which contains users information. Each entry in this file has, 7 fields,\n\n`username:password:UID:GID:Comment:home directory:shell`\n\n`username` - The name of the user.\n\n\nRemember: /etc/passwd=user info(world-readable). /etc/shadow=hashes(root-only).	projects/knowledge/interview/linux/395-what-information-is-stored-in-etcpasswd-explain-ea.txt
linux-security/69b1009b3694	linux-security	easy	linux, commands, permissions	How do you change file ownership on Linux?	`chown` (change owner). Syntax: `chown user:group file`. Examples: `chown alice file.txt` (change owner), `chown alice:devs file.txt` (owner and group), `chown :devs file.txt` (group only). Use `-R` for recursive: `chown -R alice:devs /opt/app/`. Requires root or sudo unless you own the file.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/581-chown-command.txt
linux-security/6bbf7f2cf38a	linux-security	hard	encryption, linux, system	Which algorithms are supported in `/etc/shadow` file?	Typical current algorithms are:\n\n- MD5\n- SHA-1 (also called SHA)\n\nboth should not be used for cryptographic/security purposes any more!!\n\n- SHA-256\n- SHA-512\n- SHA-3 (KECCAK was announced the winner in the competition for a new federal approved hash algorithm in October 2012)\n\nRemember: /etc/passwd=user info(world-readable). /etc/shadow=hashes(root-only).	projects/knowledge/interview/linux/062-which-algorithms-are-supported-in-codeetcshadowcod.txt
linux-security/6c7f30eb17b4	linux-security	easy	linux, permissions, users	Explain what is setgid and setuid	* setuid is a linux file permission that permits a user to run a file or program with the permissions of the owner of that file. This is possible by elevation of current user privileges.\n* setgid is a process when executed will run as the group that owns the file.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/161-explain-what-is-setgid-and-setuid.txt
linux-security/6d52b0b534bd	linux-security	easy	linux, users, security	How to add a new user to the system without providing a password?	Several methods:\n\nuseradd without password:\n- useradd -m username (creates user, no password set)\n- Account is locked until password set\n\nSet empty password (not recommended):\n- passwd -d username (deletes password)\n\nSSH key authentication (recommended):\n- useradd -m username\n- mkdir /home/username/.ssh\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/396-how-to-add-a-new-user-to-the-system-without-provid.txt
linux-security/6d74b7bdceeb	linux-security	hard	audit, linux, selinux, ssh, system	Which way of additionally feeding random entropy pool would you suggest for producing random passwords? How to improve it?	You should use `/dev/urandom`, not `/dev/random`. The two differences between `/dev/random` and `/dev/urandom` are:\n\n - `/dev/random` might be theoretically better _in the context of an information-theoretically secure algorithm_. This is the kind of algorithm which is secure against today's technology, and also tomorrow's technology, and technology used by aliens, and God's own iPad as well.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/098-which-way-of-additionally-feeding-random-entropy-p.txt
linux-security/711a3d10bd8d	linux-security	medium	linux, permissions, system, users	How does the sticky bit work? The `SUID/GUID` is the same?	This is probably one of my most irksome things that people mess up all the time. The **SUID/GUID** bit and the **sticky-bit** are 2 completely different things.\n\nIf you do a `man chmod` you can read about the **SUID** and **sticky-bits**.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/046-how-does-the-sticky-bit-work-the-codesuidguidcode-.txt
linux-security/72fdc0dfe4a5	linux-security	hard	linux, security, fork-bomb, denial-of-service, ulimit	What happens when you run :(){ :|:& };: and why is it dangerous?	This is a fork bomb - a denial-of-service attack that rapidly exhausts system resources.\n\nBreaking down the syntax:\n- `:()` - defines a function named ':'\n- `{ :|:& }` - function body: calls itself, pipes to another copy of itself, runs in background\n- `;:` - end definition and execute the function\n\nWhat happens:\n1. Function calls itself twice (via pipe)\n2.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/516-fork-bomb-explanation.txt
linux-security/746b78bd38eb	linux-security	easy	linux, commands, permissions	How do you change file permissions on Linux?	`chmod` (change mode). Two forms: symbolic (`chmod u+x script.sh`) and octal (`chmod 755 script.sh`). Octal digits: 4=read, 2=write, 1=execute — e.g. 755 means rwxr-xr-x (owner full, group/others read+execute). Use `-R` for recursive. Common patterns: `chmod 600 secrets.key` (owner-only), `chmod +x deploy.sh` (make executable).\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/580-chmod-command.txt
linux-security/768f8c1982d6	linux-security	easy	linux, packages, permissions	True or False? In order to install packages on the system you must have root privileges.	Generally TRUE, but with exceptions:\n\nTRUE because:\n- System packages install to protected paths (/usr, /etc)\n- Package managers (apt, yum, dnf) require root\n\nExceptions:\n- User-level: pip install --user, npm install, cargo install\n- Containerized: Docker/Podman, Flatpak, Snap with user scope\n- Rootless: Nix with user profiles, Homebrew\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/331-true-or-false-in-order-to-install-packages-on-the-.txt
linux-security/78d31071fc49	linux-security	medium	linux, security, capabilities, setuid	Capabilities vs setuid?	setuid grants full root privileges.\n\nCapabilities grant fine-grained privileges (e.g. `CAP_NET_BIND_SERVICE`)—least privilege model.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/547-capabilities-vs-setuid.txt
linux-security/81bbf79b1db9	linux-security	medium	linux, users	How do you change/set the password of a user?	`passwd <username>` is the command to set/change password of a user.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/392-how-do-you-changeset-the-password-of-a-user.txt
linux-security/869ba156f956	linux-security	easy	linux, users	What is the UID the root user? What about a regular user?	Re-install the OS IS NOT the right answer :)\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/272-what-is-the-uid-the-root-user-what-about-a-regular.txt
linux-security/8f9963373d10	linux-security	medium	linux, system, users	How to run script as another user without password?	For example (with `visudo` command):\n\n```bash\nuser1 ALL=(user2) NOPASSWD: /opt/scripts/bin/generate.sh\n```\n\nThe command paths must be absolute! Then call `sudo -u user2 /opt/scripts/bin/generate.sh` from a user1 shell.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/068-how-to-run-script-as-another-user-without-password.txt
linux-security/91274f816575	linux-security	easy	linux, kerberos, security, authentication	What is Kerberos and how does it handle authentication?	Kerberos is a network authentication protocol using tickets.\n\nComponents:\n- KDC (Key Distribution Center): Auth server\n- TGT (Ticket Granting Ticket): Initial auth token\n- Service tickets: Access specific services\n- Principal: User or service identity\n\nHow it works:\n1. User authenticates to KDC, gets TGT\n2. TGT used to request service tickets\n3.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/366-what-is-kerberos.txt
linux-security/921c6cbee0db	linux-security	easy	linux, permissions, security	What is the difference between a User and a Superuser?	A User has limited access; a Superuser (root) has unlimited permissions.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/558-user-vs-superuser.txt
linux-security/95b384863da4	linux-security	medium	linux, permissions, users	What this command does? chmod +x some_file	It adds execute permissions to all sets i.e user, group and others\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/160-what-this-command-does-chmod-x-somefile.txt
linux-security/97bf690f17d7	linux-security	hard	linux, permissions, system	Other admin trying to debug a server accidentally typed: `chmod -x /bin/chmod`. How to reset permissions back to default?	```bash\n# 1:\ncp /bin/ls chmod.01\ncp /bin/chmod chmod.01\n./chmod.01 700 file\n\n# 2:\n/bin/busybox chmod 0700 /bin/chmod\n\n# 3:\nsetfacl --set u::rwx,g::---,o::--- /bin/chmod\n\n# 4:\n/usr/lib/ld*.so /bin/chmod 0700 /bin/chmod\n```\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/119-other-admin-trying-to-debug-a-server-accidentally-.txt
linux-security/9a8452baabff	linux-security	easy	linux, commands, sudo, security	What does the sudo command do?	It allows a permitted user to execute a command as the superuser (root) or another user, elevating privileges for that command.\n\nRemember: sudo config: `/etc/sudoers`. ALWAYS edit with `visudo` — validates syntax.\n\nGotcha: Broken sudoers = locked out. visudo prevents by checking before saving.	projects/knowledge/interview/linux/562-what-does-sudo-do.txt
linux-security/acc907db7533	linux-security	hard	encryption, linux, pam, permissions, system	Ordinary users are able to read `/etc/passwd`. Is it a security hole? Do you know other password shadowing scheme?	Typically, the _hashed passwords_ are stored in `/etc/shadow` on most Linux systems:\n\n```bash\n-rw-r----- 1 root shadow 1349 2016-07-03 03:54 /etc/shadow\n```\n\nThey are stored in `/etc/master.passwd` on BSD systems.\n\n\nRemember: /etc/passwd=user info(world-readable). /etc/shadow=hashes(root-only).	projects/knowledge/interview/linux/090-ordinary-users-are-able-to-read-codeetcpasswdcode-.txt
linux-security/aedf3aff9877	linux-security	medium	linux, users	True or False? It's not possible to have a root user with ID 0 in child user namespaces	False. In every child user namespace, it's possible to have a separate root user with uid of 0.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/284-true-or-false-its-not-possible-to-have-a-root-user.txt
linux-security/b4ac446df8bc	linux-security	hard	linux, security, hardening	Do you have experience with hardening servers? Can you describe the process?	Server hardening reduces attack surface and vulnerabilities.\n\nKey areas:\n1. Updates: Keep system patched\n2. Users: Disable root login, use sudo, strong passwords\n3. SSH: Key-only auth, change port, fail2ban\n4. Firewall: Allow only needed ports\n5. Services: Disable unnecessary services\n6. File permissions: Proper ownership, no world-writable\n7. SELinux/AppArmor: Enable MAC\n8.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/369-do-you-have-experience-with-hardening-servers-can-.txt
linux-security/b65938dbe360	linux-security	medium	audit, linux, system, users	I have forgotten the root password! What do I do in BSD? What is the purpose of booting into single user mode?	Restart the system, type `boot -s` at the `Boot:` prompt to enter **single-user mode**.\n\nAt the question about the shell to use, hit `Enter` which will display a `#` prompt.\n\nEnter `mount -urw /` to remount the root file system read/write, then run `mount -a` to remount all the file systems.\n\nRun `passwd root` to change the root password then run `exit` to continue booting.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/049-i-have-forgotten-the-root-password-what-do-i-do-in.txt
linux-security/be3509a1b22e	linux-security	medium	linux, users	You run grep $(whoami) /etc/passwd but the output is empty. What might be a possible reason for that?	The user you are using isn't defined locally but originates from services like LDAP. \nYou can verify with: `getent passwd`\n\nRemember: /etc/passwd=user info(world-readable). /etc/shadow=hashes(root-only).	projects/knowledge/interview/linux/275-you-run-grep-whoami-etcpasswd-but-the-output-is-em.txt
linux-security/c60bf4c02459	linux-security	medium	linux, users	Which file stores information about groups?	`/etc/groups` file stores the group name, group ID, usernames which are in secondary group.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/391-which-file-stores-information-about-groups.txt
linux-security/cda0995d7569	linux-security	medium	apparmor, linux, permissions, system	What is umask? How to set it permanently for a user?	"On Linux and other Unix-like operating systems, new files are created with a default set of permissions. Specifically, a new file's permissions may be restricted in a specific way by applying a permissions ""mask"" called the `umask`. The `umask` command is used to set this mask, or to show you its current value.\n\nPermanently change (set e.g. `umask 02`):\n\n- `~/.profile`\n- `~/.bashrc`\n- `~/.zshrc`\n- `~/.cshrc`"\n\nRemember: umask subtracts from 666(files)/777(dirs). 022→644/755. "What to remove."	projects/knowledge/interview/linux/043-what-is-umask-how-to-set-it-permanently-for-a-user.txt
linux-security/cfacd9c6a8df	linux-security	hard	audit, linux, system, users	What is this UID 0 toor account? Have I been compromised?	**toor** is an alternative superuser account, where toor is root spelled backwards. It is intended to be used with a non-standard shell so the default shell for root does not need to change.\n\nThis is important as shells which are not part of the base distribution, but are instead installed from ports or packages, are installed in `/usr/local/bin` which, by default, resides on a different file sy\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/078-what-is-this-uid-0-toor-account-have-i-been-compro.txt
linux-security/d6ac09dfe229	linux-security	hard	apparmor, linux, permissions, security, selinux	What is the difference between DAC and MAC?	Two fundamentally different access control models:\n\n**DAC (Discretionary Access Control)**:\n* Traditional Unix permissions (rwx)\n* Owner controls access to their objects\n* Users can change permissions on their files\n* Root bypasses all checks\n* Vulnerable to privilege escalation\n\n**MAC (Mandatory Access Control)**:\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/464-what-is-difference-between-dac-and-mac.txt
linux-security/db842c219f01	linux-security	medium	linux, permissions, system, users	How and why Linux daemons drop privileges? Why some daemons need root permissions to start? Explain. 	"The problem with a load of 1.00 is that you have no headroom. In practice, many sysadmins will draw a line at 0.70.\n\nThe ""Need to Look into it"" Rule of Thumb: 0.70 If your load average is staying above > 0.70, it's time to investigate before things get worse.\n"\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/036-how-and-why-linux-daemons-drop-privileges-why-some.txt
linux-security/dd1af651501c	linux-security	medium	linux, permissions, users	A user accidentally executed the following chmod -x $(which chmod). How to fix it?	Using `sudo setfacl -m u::rx /usr/bin/chmod` will set the execute permissions on `chmod` for all the users. Post this, the `chmod` binary can be used as usual.\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	projects/knowledge/interview/linux/167-a-user-accidentally-executed-the-following-chmod-x.txt
linux-security/e373b39f3abd	linux-security	hard	encryption, linux, ssh, system	How to check whether the private key and the certificate match?	```bash\n(openssl rsa -noout -modulus -in private.key | openssl md5 ; openssl x509 -noout -modulus -in certificate.crt | openssl md5) | uniq\n```\n\nRemember: TLS port 443. Chain: Root CA→Intermediate→Server. Let's Encrypt=free, 90-day.	projects/knowledge/interview/linux/121-how-to-check-whether-the-private-key-and-the-certi.txt
linux-security/e3ae048cad4c	linux-security	easy	linux, security, root, permissions	What is a superuser or root user? How is it different from regular users?	Root (UID 0) is the superuser with unrestricted access.\n\nRoot capabilities:\n- Access all files regardless of permissions\n- Modify any system configuration\n- Bind to privileged ports (<1024)\n- Load kernel modules\n- Mount filesystems\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/389-what-is-a-superuser-or-root-user-how-is-it-differe.txt
linux-security/ef81a9657041	linux-security	easy	linux, commands, chown, permissions	How do you change the owner of a file in Linux?	Using the chown command (e.g., chown user:group filename).\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/565-change-owner-of-file.txt
linux-security/f32136f77272	linux-security	medium	linux, users	Do you know how to create a new user without using adduser/useradd command?	YES, we can create new user by manually adding an entry in the `/etc/passwd` file. \n\nFor example, if we need to create a user called `john`. \n\nStep 1: Add an entry to `/etc/passwd` file, so user gets created.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/394-do-you-know-how-to-create-a-new-user-without-using.txt
linux-security/f9dcc2834649	linux-security	easy	linux, selinux, security	What is SELinux and how does it enforce mandatory access control?	SELinux (Security-Enhanced Linux) is a mandatory access control (MAC) system.\n\nFeatures:\n- Fine-grained access control beyond standard permissions\n- Labels on files, processes, ports\n- Policy defines allowed actions\n- Developed by NSA, in mainline kernel\n\nModes:\n- Enforcing: Blocks and logs violations\n\nRemember: SELinux: Enforcing, Permissive, Disabled. Check: `getenforce`. "EPD."\n\nGotcha: `setenforce 0` is temporary. Permanent: `/etc/selinux/config`. Disabling breaks compliance.	projects/knowledge/interview/linux/365-what-is-seliunx.txt
linux-security/face93a92a01	linux-security	medium	hardening, linux, system, users	Your friend during configuration of the MySQL server asked you: <i>Should I run `sudo mysql_secure_installation` after installing mysql?</i> What do you think about it?	It would be better if you run command as it provides many security options like:\n\n- You can set a password for root accounts\n- You can remove root accounts that are accessible from outside the local host\n- You can remove anonymous-user accounts\n- You can remove the test database, which by default can be accessed by anonymous users\n\nRemember: sudo config: `/etc/sudoers`. ALWAYS edit with `visudo` — validates syntax.\n\nGotcha: Broken sudoers = locked out. visudo prevents by checking before saving.	projects/knowledge/interview/linux/059-your-friend-during-configuration-of-the-mysql-serv.txt
linux-security/fb8378309839	linux-security	hard	encryption, linux, system	What are salted hashes? Generate the password with salt for the `/etc/shadow` file.	**Salt** at its most fundamental level is random data. When a properly protected password system receives a new password, it will create a hashed value for that password, create a new random salt value, and then store that combined value in its database. This helps defend against dictionary attacks and known hash attacks.\n\n\nRemember: /etc/passwd=user info(world-readable). /etc/shadow=hashes(root-only).	projects/knowledge/interview/linux/126-what-are-salted-hashes-generate-the-password-with-.txt
linux-security/fcdae2eed350	linux-security	hard	audit, hardening, linux, ssh, system	You have configured an RSA key login but your server show `Server refused our key` as expected. Where will you look for the cause of the problem?	**Server side**\n\nSetting `LogLevel VERBOSE` in file `/etc/ssh/sshd_config` is probably what you need, although there are higher levels:\n\nSSH auth failures are logged in `/var/log/auth.log`, `/var/log/secure` or `/var/log/audit/audit.log`.\n\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/065-you-have-configured-an-rsa-key-login-but-your-serv.txt
linux-security/z4d5e6f7a8b9	linux-security	medium	linux,permissions,directory,execute	What does execute permission on a directory mean vs on a file?	On a file: the file can be run as a program or script.\nOn a directory: you can traverse (cd into) and access files within it. Without execute on a directory, you cannot list or access its contents even with read permission.\n\nRemember: 4=read, 2=write, 1=execute. 755=rwxr-xr-x. SUID=4000, SGID=2000, sticky=1000.\n\nGotcha: SUID runs as owner(root). Find: `find / -perm -4000`. Security audit must-check.	zines/bite.size.linux.cleaned.notes
linux-security/z8b9c0d1e2f3	linux-security	easy	linux,umask,permissions	What does umask control?	The default permission mask for newly created files and directories. umask is subtracted from the maximum permissions (666 for files, 777 for directories) to determine the actual permissions.\n\nRemember: umask subtracts from 666(files)/777(dirs). 022→644/755. "What to remove."	zines/bite.size.linux.cleaned.notes
linux-security/a1b2c3d4e5f6	linux-security	easy	linux-hardening, selinux, modes	What are the three SELinux modes, and how do you check the current mode?	Enforcing (policies enforced, violations blocked and logged), Permissive (policies not enforced, violations logged only), Disabled (SELinux completely off). Check with getenforce (quick) or sestatus (detailed). Use setenforce 0/1 to toggle temporarily; edit /etc/selinux/config for persistence.\n\nRemember: SELinux: Enforcing, Permissive, Disabled. Check: `getenforce`. "EPD."\n\nGotcha: `setenforce 0` is temporary. Permanent: `/etc/selinux/config`. Disabling breaks compliance.	training/library/topics/linux-hardening/primer.md
linux-security/b2c3d4e5f6a7	linux-security	easy	linux-hardening, ssh, configuration	Name five SSH hardening settings you should configure in /etc/ssh/sshd_config.	PermitRootLogin no, PasswordAuthentication no (use keys only), MaxAuthTries 3, X11Forwarding no, and AllowUsers <specific-users>. Additional settings: ClientAliveInterval 300, ClientAliveCountMax 2, LogLevel VERBOSE. Always restrict ciphers and MACs to strong algorithms.\n\nRemember: SSH hardening: disable root, disable passwords, use keys, fail2ban. `/etc/ssh/sshd_config`.\n\nExample: `ssh-keygen -t ed25519` — modern, fast, secure. Ed25519 > RSA.	training/library/topics/linux-hardening/primer.md
linux-security/c3d4e5f6a7b8	linux-security	easy	linux-hardening, suid-sgid, permissions	How do you find SUID and SGID binaries on a system, and why should you audit them?	find / -type f \( -perm -4000 -o -perm -2000 \) -exec ls -la {} \; 2>/dev/null. SUID binaries run with the file owner's privileges (often root), making them privilege escalation vectors. SGID binaries run with the group's privileges. Audit them regularly and remove unnecessary SUID bits with chmod u-s.\n\nRemember: auditd = kernel audit. Rules: `/etc/audit/rules.d/`. Required for compliance.	training/library/topics/linux-hardening/primer.md
linux-security/d4e5f6a7b8c9	linux-security	medium	linux-hardening, cis-benchmarks, compliance	What are CIS Benchmarks, and what categories do they cover for Linux hardening?	CIS (Center for Internet Security) Benchmarks are the gold standard for compliance auditing. Categories include: filesystem configuration, software updates, filesystem integrity (AIDE), boot settings, process hardening (ASLR, core dumps), mandatory access control (SELinux), network configuration, firewall, logging/auditing, PAM/password policies, SSH configuration, and user accounts.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	training/library/topics/linux-hardening/primer.md
linux-security/e5f6a7b8c9d0	linux-security	medium	linux-hardening, pam, password-policy	How do you configure PAM to enforce password complexity and lock accounts after failed login attempts?	Password complexity: use pam_pwquality.so with options like minlen=14, dcredit=-1, ucredit=-1, ocredit=-1, lcredit=-1. Account lockout: use pam_faillock.so with deny=5 and unlock_time=900 (lock for 15 minutes after 5 failures). Restrict su to wheel group with pam_wheel.so use_uid in /etc/pam.d/su.\n\nRemember: PAM types: auth, account, password, session. Config: `/etc/pam.d/`. "AAPS."	training/library/topics/linux-hardening/primer.md
linux-security/f6a7b8c9d0e1	linux-security	medium	linux-hardening, sysctl, kernel-hardening	Name five important sysctl settings for Linux hardening and explain what they do.	kernel.randomize_va_space=2 (enable ASLR), net.ipv4.tcp_syncookies=1 (SYN flood protection), net.ipv4.conf.all.accept_redirects=0 (disable ICMP redirects), kernel.dmesg_restrict=1 (restrict dmesg to root), kernel.yama.ptrace_scope=1 (restrict process tracing). Persist in /etc/sysctl.d/99-hardening.conf and apply with sysctl -p.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	training/library/topics/linux-hardening/primer.md
linux-security/a7b8c9d0e1f2	linux-security	medium	linux-hardening, selinux, troubleshooting	An application cannot read files in its data directory due to SELinux. How do you diagnose and fix this?	1) Check for denials: ausearch -m avc -ts recent. 2) Inspect file contexts: ls -Z on the directory. 3) If wrong context, fix with: semanage fcontext -a -t <correct_type> "/path/to/data(/.*)?" then restorecon -Rv /path/to/data/. 4) Check booleans: getsebool -a | grep <service>. 5) If a boolean fix exists, use setsebool -P <boolean> on.\n\nRemember: SELinux: Enforcing, Permissive, Disabled. Check: `getenforce`. "EPD."\n\nGotcha: `setenforce 0` is temporary. Permanent: `/etc/selinux/config`. Disabling breaks compliance.	training/library/topics/linux-hardening/primer.md
linux-security/b8c9d0e1f2a3	linux-security	medium	linux-hardening, auditd, monitoring	How do you configure auditd to monitor changes to critical system files?	Add watch rules to /etc/audit/rules.d/hardening.rules. Examples: -w /etc/passwd -p wa -k identity (watch passwd for writes/attribute changes), -w /etc/shadow -p wa -k identity, -w /etc/sudoers -p wa -k actions, -w /etc/ssh/sshd_config -p wa -k sshd. The -k flag sets a key for searching. Make config immutable with -e 2 (requires reboot to change).\n\nRemember: auditd = kernel audit. Rules: `/etc/audit/rules.d/`. Required for compliance.	training/library/topics/linux-hardening/primer.md
linux-security/c9d0e1f2a3b4	linux-security	hard	linux-hardening, selinux, contexts	Explain the SELinux context format and how type enforcement works in targeted policy.	Context format: user:role:type:level. In targeted policy, the type field matters most. Processes have types (e.g., httpd_t) and files have types (e.g., httpd_sys_content_t). Policy rules define which process types can access which file types. For example, httpd_t can read httpd_sys_content_t but not other types, confining Apache even if it is compromised.\n\nRemember: SELinux: Enforcing, Permissive, Disabled. Check: `getenforce`. "EPD."\n\nGotcha: `setenforce 0` is temporary. Permanent: `/etc/selinux/config`. Disabling breaks compliance.	training/library/topics/linux-hardening/primer.md
linux-security/d0e1f2a3b4c5	linux-security	hard	linux-hardening, selinux, policy-module	How do you create a custom SELinux policy module to allow a specific denied action?	1) Find the denial: ausearch -m avc -ts recent. 2) Generate a policy module: ausearch -m avc -ts recent | audit2allow -M mypolicy. 3) Review the generated policy: cat mypolicy.te (verify it is not overly permissive). 4) Install the module: semodule -i mypolicy.pp. Always review before applying -- audit2allow can generate overly broad policies that weaken security.\n\nRemember: SELinux: Enforcing, Permissive, Disabled. Check: `getenforce`. "EPD."\n\nGotcha: `setenforce 0` is temporary. Permanent: `/etc/selinux/config`. Disabling breaks compliance.	training/library/topics/linux-hardening/primer.md
linux-security/e1f2a3b4c5d6	linux-security	hard	linux-hardening, pitfalls, persistence	What are the most common Linux hardening mistakes that undermine security?	Disabling SELinux instead of fixing the policy. Not persisting changes (setenforce 1 and sysctl -w do not survive reboot). Leaving default SSH keys. Blindly applying CIS benchmarks without understanding the workload. Auditing every syscall (fills disk, degrades performance). Building hardened AMIs that drift without re-hardening. Not testing changes in staging first.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	training/library/topics/linux-hardening/primer.md
linux-security/612eaafeb986	linux-security	easy	linux, system	What is a CLI? Tell me about your favorite CLI tools, tips, and hacks.	**CLI** (Command Line Interface) is a text-based interface for interacting with the OS by typing commands.\n\nKey concepts:\n- Shell (bash, zsh) interprets and executes commands\n- Commands follow the pattern: `command [options] [arguments]`\n- Supports piping (`|`), redirection (`>`, `<`), and scripting\n- More powerful than GUI for automation, remote access (SSH), and batch operations\n\nEssential for DevOps: nearly all server administration, CI/CD, and infrastructure management happens via CLI.\n\nRemember: Security layers: perms, sudo, firewall, SELinux/AppArmor, auditing.\n\nGotcha: Defense in depth — no single layer is enough.	projects/knowledge/interview/linux/003-what-is-a-cli-tell-me-about-your-favorite-cli-tool.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Compliance & Audit Automation](../../../../library/topics/compliance-automation/index.md) (Topic Pack, L2) — Linux Hardening
- [Deep Dive: Systemd Service Design Debugging and Hardening](../../../../library/deep-dives/systemd.service.design.debugging.and.hardening.md) (deep_dive, L2) — Linux Hardening
- [Infrastructure Forensics](../../../../library/topics/infra-forensics/index.md) (Topic Pack, L2) — Linux Hardening
- [LDAP & Identity Management](../../../../library/topics/ldap-identity/index.md) (Topic Pack, L2) — Linux Hardening
- [Linux Users & Permissions](../../../../library/topics/linux-users-and-permissions/index.md) (Topic Pack, L1) — Linux Hardening
- [SELinux & AppArmor](../../../../library/topics/selinux-apparmor/index.md) (Topic Pack, L2) — Linux Hardening
- [SELinux & Linux Hardening](../../../../library/topics/linux-hardening/index.md) (Topic Pack, L2) — Linux Hardening
- [SSH Deep Dive](../../../../library/topics/ssh-deep-dive/index.md) (Topic Pack, L1) — Linux Hardening

<!-- wiki:related:end -->
