I2: Linux Basics for Security
Build safe Linux foundations for understanding system roles, paths, accounts, permissions, processes, services, logs, updates, and defensive administration.
Module Snapshot
Intermediate
Track
I2 of 17
Module
8
Lessons
25 questions
Module test
Systems defense begins here
This module adds Linux structure, account and permission review, process and service context, safe terminal reading, log correlation, and controlled update reasoning.
Main Question
How do defenders understand a Linux system well enough to protect it without making unsafe or unsupported changes?
Students will connect system role, paths, users, groups, permissions, processes, services, logs, packages, ownership, and approved change records before recommending defensive actions.
Safety Boundary
Every Linux host, account, directory, permission, process, service, package, command output, log, and organization in this module is fictional. Practice stays read-only, authorized, and limited to supplied training evidence.
Professional Workflow
Identify, Observe, Correlate, Compare, and Document
Identify
Confirm the fictional system role, owner, environment, sensitivity, exposure, and approved purpose.
Observe
Review files, directories, accounts, groups, permissions, processes, services, packages, and logs.
Correlate
Connect users, owners, paths, timestamps, service activity, updates, and change records.
Compare
Check observed state against the approved baseline, least privilege, system role, and maintenance plan.
Document
Record confirmed facts, uncertainty, risk, owner, recommendation, validation, and rollback.
Learning Objectives
What Students Will Be Able to Do
Explain how Linux distributions, kernels, shells, services, and system roles connect in a defensive environment.
Navigate fictional Linux file systems and interpret important paths without changing real systems.
Review users, groups, ownership, and permissions using least privilege and approved purpose.
Connect processes and services with owners, dependencies, startup behavior, ports, and logs.
Interpret safe command-line output and distinguish observation from system modification.
Correlate Linux logs, package records, inventories, and changes into evidence-based defensive conclusions.
Module Path
Eight Intermediate Lessons
Each lesson includes professional hooks, fictional system evidence, safe defensive labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.
I2.1
Lesson 1
Linux Systems and Security Roles
Understand where Linux is used, how distributions differ, and why defenders review system roles, ownership, and approved purpose.
Defensive Lab
Classify fictional Linux systems by role, sensitivity, owner, exposure, and defensive responsibility.
I2.2
Lesson 2
Files, Directories, and Paths
Read Linux paths, distinguish common system directories, and connect file location with purpose, ownership, and evidence.
Defensive Lab
Organize a fictional directory map and identify expected, sensitive, temporary, and review-required locations.
I2.3
Lesson 3
Users, Groups, and Permissions
Interpret user, group, ownership, and read-write-execute permission concepts using least privilege and approved access.
Defensive Lab
Review fictional account and permission records and recommend safer, narrower access.
I2.4
Lesson 4
Processes and Services
Connect running processes and background services with system roles, owners, dependencies, startup behavior, and logs.
Defensive Lab
Analyze a fictional process and service inventory for expected, stopped, duplicate, stale, and review-required entries.
I2.5
Lesson 5
Safe Command-Line Navigation
Use safe, read-only command-line concepts to understand the current location, list files, inspect context, and avoid risky assumptions.
Defensive Lab
Complete a fictional read-only terminal navigation challenge without changing system state.
I2.6
Lesson 6
Linux Logs and System Clues
Read fictional authentication, service, system, and application log clues while respecting timestamps and evidence limits.
Defensive Lab
Correlate fake Linux log entries into a defensive timeline and separate facts from likely explanations.
I2.7
Lesson 7
Package Updates and System Care
Understand trusted repositories, package versions, update planning, restart needs, validation, rollback, and system maintenance.
Defensive Lab
Prioritize fictional Linux updates using asset role, exposure, severity, compatibility, owner, and change windows.
I2.8
Lesson 8
Linux Security Basics Lab
Combine roles, paths, users, groups, permissions, processes, services, logs, and updates into one defensive review.
Defensive Lab
Complete a multi-source fictional Linux security assessment and write an evidence-based improvement plan.
Fake Evidence Preview
How Intermediate Linux Evidence Connects
08:41:12
Inventory
training-web-02 role confirmed as internal learning portal
Provides approved system purpose, owner, environment, and expected services.
08:43:27
Account
Temporary support account remains enabled after project end
Shows current account state but still requires ownership and dependency review.
08:45:06
Permission
/srv/training-content group write granted to all staff
Indicates broader access than the current content-owner group appears to require.
08:47:33
Service Log
Approved web service healthy; legacy sync service still starts
Connects service state with a possible stale dependency that needs validation.
Portfolio Outcome
Linux Security Review Report
Students will build a fictional report containing a system-role summary, directory map, account and permission review, process and service inventory, log timeline, update plan, evidence limits, risk priorities, and authorized next actions.
Module Assessment
25-Question I2 Module Test
The test will cover Linux structure, files and paths, users, groups, permissions, processes, services, safe navigation, logs, package updates, system care, and defensive system reasoning. Answers stay hidden until submission.
Open Module Test