Security & Hardening
Security & Hardening
7 interactive questions
SELinux vs AppArmor?
SELinux — mandatory access control (MAC), labels on everything, policy-driven, complex but granular (RHEL/Fedora). AppArmor — path-based MAC, profile per binary, easier to write (Ubuntu/SUSE). Both enforce least privilege beyond DAC.
How do you check and change SELinux mode?
getenforce (Enforcing/Permissive/Disabled). setenforce 0 (temporary Permissive). Permanent: edit /etc/selinux/config (SELINUX=enforcing). Relabel on boot: touch /.autorelabel; reboot.
How do you harden SSH?
/etc/ssh/sshd_config: PermitRootLogin no, PasswordAuthentication no, PubkeyAuthentication yes, Port 2222 (non-standard), MaxAuthTries 3, ClientAliveInterval 300, AllowUsers user1 user2. Then systemctl reload sshd.
What is `fail2ban` and how does it work?
Scans logs (sshd, nginx, etc.) for failed auth patterns, then bans offending IPs via firewall (iptables/nftables) for a configurable time. jail.local defines filters, actions, bantime, maxretry.
What is `auditd` and what does it track?
Kernel audit subsystem. Rules in /etc/audit/rules.d/. Tracks: file access (-w /etc/passwd -p wa), syscalls (-a always,exit -S open), commands (-a always,exit -F arch=b64 -S execve). Query with ausearch, aureport.
How do you audit a Linux system?
Run Lynis (lynis audit system) — comprehensive scanner for hardening, vulnerabilities, compliance. Also: openscap, scap-security-guide. Check CIS benchmarks.
What is the difference between DAC, MAC, and RBAC?
DAC (Discretionary) — traditional Unix permissions (owner decides). MAC (Mandatory) — kernel enforces policy (SELinux, AppArmor). RBAC (Role-Based) — users assigned roles, roles granted permissions (Kubernetes, cloud IAM). 🎯 MAC overrides DAC.