Hardening Linux Systems
Turn a default Linux install into one that resists real attackers: SSH keys, sudo, firewalls, fail2ban, mandatory access control, and permissions as a security tool.
What you'll actually learn
A default Linux install is configured to work, not to resist an attacker — password auth is on, the firewall is often wide open, and sudo is one weak password away from full root. This track walks through hardening it piece by piece: switching to SSH keys, locking down sudo properly, writing real firewall rules instead of copy-pasted ones, setting up fail2ban to actually respond to brute-force attempts, and using mandatory access control instead of hoping file permissions are enough.
What you'll be able to do
You'll take a freshly installed server and turn it into one you'd actually be comfortable exposing to the internet — able to explain exactly what each hardening step defends against, not just that "it's more secure." That's the difference examiners and interviewers are actually probing for when they ask how you'd secure a box.
Syllabus
Leads to
Frequently asked
Roughly 2 hours across 9 hands-on quests — you can go at your own pace and pick up exactly where you left off.
Nothing — this is one of the starting points in the skill tree, no prior skill required.
Yes — Hardening Linux Systems is fully available on the free tier, starting with a free first quest and no payment method required to sign up. Plus and Elite remove pacing limits but don't gate any of the Hardening Linux Systems curriculum behind a paywall.
Create a free account and begin your first quest — no card required.
Start free