High School IntermediateModule I2 of 17Defensive Only

I2: Linux Basics for Security

Build safe Linux foundations for understanding system roles, paths, accounts, permissions, processes, services, logs, updates, and defensive administration.

Module Snapshot

Intermediate

Track

I2 of 17

Module

8

Lessons

25 questions

Module test

Systems defense begins here

This module adds Linux structure, account and permission review, process and service context, safe terminal reading, log correlation, and controlled update reasoning.

Main Question

How do defenders understand a Linux system well enough to protect it without making unsafe or unsupported changes?

Students will connect system role, paths, users, groups, permissions, processes, services, logs, packages, ownership, and approved change records before recommending defensive actions.

Safety Boundary

Every Linux host, account, directory, permission, process, service, package, command output, log, and organization in this module is fictional. Practice stays read-only, authorized, and limited to supplied training evidence.

Professional Workflow

Identify, Observe, Correlate, Compare, and Document

1

Identify

Confirm the fictional system role, owner, environment, sensitivity, exposure, and approved purpose.

2

Observe

Review files, directories, accounts, groups, permissions, processes, services, packages, and logs.

3

Correlate

Connect users, owners, paths, timestamps, service activity, updates, and change records.

4

Compare

Check observed state against the approved baseline, least privilege, system role, and maintenance plan.

5

Document

Record confirmed facts, uncertainty, risk, owner, recommendation, validation, and rollback.

Learning Objectives

What Students Will Be Able to Do

Explain how Linux distributions, kernels, shells, services, and system roles connect in a defensive environment.

Navigate fictional Linux file systems and interpret important paths without changing real systems.

Review users, groups, ownership, and permissions using least privilege and approved purpose.

Connect processes and services with owners, dependencies, startup behavior, ports, and logs.

Interpret safe command-line output and distinguish observation from system modification.

Correlate Linux logs, package records, inventories, and changes into evidence-based defensive conclusions.

Module Path

Eight Intermediate Lessons

Each lesson includes professional hooks, fictional system evidence, safe defensive labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.

I2.1

Lesson 1

Linux Systems and Security Roles

Understand where Linux is used, how distributions differ, and why defenders review system roles, ownership, and approved purpose.

Defensive Lab

Classify fictional Linux systems by role, sensitivity, owner, exposure, and defensive responsibility.

Open →

I2.2

Lesson 2

Files, Directories, and Paths

Read Linux paths, distinguish common system directories, and connect file location with purpose, ownership, and evidence.

Defensive Lab

Organize a fictional directory map and identify expected, sensitive, temporary, and review-required locations.

Open →

I2.3

Lesson 3

Users, Groups, and Permissions

Interpret user, group, ownership, and read-write-execute permission concepts using least privilege and approved access.

Defensive Lab

Review fictional account and permission records and recommend safer, narrower access.

Open →

I2.4

Lesson 4

Processes and Services

Connect running processes and background services with system roles, owners, dependencies, startup behavior, and logs.

Defensive Lab

Analyze a fictional process and service inventory for expected, stopped, duplicate, stale, and review-required entries.

Open →

I2.5

Lesson 5

Safe Command-Line Navigation

Use safe, read-only command-line concepts to understand the current location, list files, inspect context, and avoid risky assumptions.

Defensive Lab

Complete a fictional read-only terminal navigation challenge without changing system state.

Open →

I2.6

Lesson 6

Linux Logs and System Clues

Read fictional authentication, service, system, and application log clues while respecting timestamps and evidence limits.

Defensive Lab

Correlate fake Linux log entries into a defensive timeline and separate facts from likely explanations.

Open →

I2.7

Lesson 7

Package Updates and System Care

Understand trusted repositories, package versions, update planning, restart needs, validation, rollback, and system maintenance.

Defensive Lab

Prioritize fictional Linux updates using asset role, exposure, severity, compatibility, owner, and change windows.

Open →

I2.8

Lesson 8

Linux Security Basics Lab

Combine roles, paths, users, groups, permissions, processes, services, logs, and updates into one defensive review.

Defensive Lab

Complete a multi-source fictional Linux security assessment and write an evidence-based improvement plan.

Open →

Fake Evidence Preview

How Intermediate Linux Evidence Connects

08:41:12

Inventory

training-web-02 role confirmed as internal learning portal

Provides approved system purpose, owner, environment, and expected services.

08:43:27

Account

Temporary support account remains enabled after project end

Shows current account state but still requires ownership and dependency review.

08:45:06

Permission

/srv/training-content group write granted to all staff

Indicates broader access than the current content-owner group appears to require.

08:47:33

Service Log

Approved web service healthy; legacy sync service still starts

Connects service state with a possible stale dependency that needs validation.

A strong conclusion uses the records together: system purpose, account state, permission scope, service activity, ownership, change history, timestamps, and current defensive need.

Portfolio Outcome

Linux Security Review Report

Students will build a fictional report containing a system-role summary, directory map, account and permission review, process and service inventory, log timeline, update plan, evidence limits, risk priorities, and authorized next actions.

Module Assessment

25-Question I2 Module Test

The test will cover Linux structure, files and paths, users, groups, permissions, processes, services, safe navigation, logs, package updates, system care, and defensive system reasoning. Answers stay hidden until submission.

Open Module Test
← Intermediate TrackStart I2.1 →