Linux hardening
Start from a default Ubuntu Server 26.04 install and harden it one control at a time: patching, fewer services, accounts and PAM, sudo, SSH, trustworthy logs and auditd, file permissions, mounts and disk encryption, systemd sandboxing and secrets, host firewalls and nftables, kernel settings and modules, AppArmor and SELinux, integrity monitoring and CIS benchmarks. Every control states the threat it addresses, how to configure and verify it, what it costs in operation, and how to roll it back, with RHEL 10 shown wherever it differs. Twenty-four lessons across eight sections, each with a self-test, and a final exam.
01Users, groups and account lifecycleUID 0, service accounts and off-boarding.14 min02PAM policy: password quality and lockoutpwquality and faillock, tested safely.16 min03Hardening sudoNarrow rules for sudo-rs and classic sudo.14 min04Hardening the SSH serverDrop-ins, verification and safe rollout.16 min05SSH keys, FIDO keys, MFA and bastionsKey lifecycle, MFA and a single entry point.16 min
Progress is saved in this browser only — no account required.
Quick reference
Final exam
Test yourself on everything
53 questions drawn from all 8 sections — every answer explained as you pick.