Security & Hardening

0%
Securityselinuxapparmorfirewallsshauditfail2banlynischattr

Security & Hardening

7 interactive questions

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

SELinux vs AppArmor?

Click to reveal answer
SecurityAnswer

SELinux — mandatory access control (MAC), labels on everything, policy-driven, complex but granular (RHEL/Fedora). AppArmor — path-based MAC, profile per binary, easier to write (Ubuntu/SUSE). Both enforce least privilege beyond DAC.

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

How do you check and change SELinux mode?

Click to reveal answer
SecurityAnswer

getenforce (Enforcing/Permissive/Disabled). setenforce 0 (temporary Permissive). Permanent: edit /etc/selinux/config (SELINUX=enforcing). Relabel on boot: touch /.autorelabel; reboot.

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

How do you harden SSH?

Click to reveal answer
SecurityAnswer

/etc/ssh/sshd_config: PermitRootLogin no, PasswordAuthentication no, PubkeyAuthentication yes, Port 2222 (non-standard), MaxAuthTries 3, ClientAliveInterval 300, AllowUsers user1 user2. Then systemctl reload sshd.

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

What is `fail2ban` and how does it work?

Click to reveal answer
SecurityAnswer

Scans logs (sshd, nginx, etc.) for failed auth patterns, then bans offending IPs via firewall (iptables/nftables) for a configurable time. jail.local defines filters, actions, bantime, maxretry.

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

What is `auditd` and what does it track?

Click to reveal answer
SecurityAnswer

Kernel audit subsystem. Rules in /etc/audit/rules.d/. Tracks: file access (-w /etc/passwd -p wa), syscalls (-a always,exit -S open), commands (-a always,exit -F arch=b64 -S execve). Query with ausearch, aureport.

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

How do you audit a Linux system?

Click to reveal answer
SecurityAnswer

Run Lynis (lynis audit system) — comprehensive scanner for hardening, vulnerabilities, compliance. Also: openscap, scap-security-guide. Check CIS benchmarks.

SecurityQuestion
selinuxapparmorfirewallsshauditfail2banlynischattr

What is the difference between DAC, MAC, and RBAC?

Click to reveal answer
SecurityAnswer

DAC (Discretionary) — traditional Unix permissions (owner decides). MAC (Mandatory) — kernel enforces policy (SELinux, AppArmor). RBAC (Role-Based) — users assigned roles, roles granted permissions (Kubernetes, cloud IAM). 🎯 MAC overrides DAC.