Bookmark this page

Chapter 12.  Comprehensive Review

Abstract

Goal

Review tasks from Red Hat Security: Linux in Physical, Virtual, and Cloud.

Sections
  • Comprehensive Review

Lab
  • Protecting Data with LUKS and NBDE

  • Restricting USB Device Access

  • Recording Events and Monitoring File-system Changes with PAM, Audit, and AIDE

  • Mitigating Risk with SELinux

  • Managing Compliance with OpenSCAP and Ansible

Comprehensive Review

Objectives

After completing this section, you should have reviewed and refreshed the knowledge and skills that you learned in Red Hat Security: Linux in Physical, Virtual, and Cloud.

Reviewing Red Hat Security: Linux in Physical, Virtual, and Cloud

Before beginning the comprehensive review for this course, you should be comfortable with the topics covered in each chapter. Do not hesitate to ask the instructor for extra guidance or clarification on these topics.

Define and implement strategies to manage security on Red Hat Enterprise Linux systems.

Remediate configuration and security issues automatically with Ansible Playbooks.

Encrypt data on storage devices with Linux Unified Key Setup (LUKS), and use Network-bound Disk Encryption (NBDE) to manage automatic decryption when servers are booted.

Protect systems from rogue USB device access with USBGuard.

Manage authentication, authorization, session settings, and password controls by configuring Pluggable Authentication Modules (PAM).

Record and inspect system events relevant to security by using the Linux kernel's Audit system and supporting tools.

Detect and analyze changes to a server's file systems and their contents by using AIDE.

Improve security and confinement between processes by using SELinux and advanced SELinux techniques and analysis.

Evaluate and remediate a server's compliance with security policies by using OpenSCAP.

Identify, detect, and correct common issues and security vulnerabilities with Red Hat Enterprise Linux systems by using Red Hat Insights.

Automate and scale OpenSCAP compliance checks by using Red Hat Satellite.

Revision: rh415-9.2-a821299