LinuC Level 3 303Security
Exam 303 Objectives
Each item of the objectives is weighted for its importance.The weight is approximately in the range 1 to 10, and indicates the relative importance of the topic covered. Questions on topics with higher weight appear more often in the exams.
Topic 325: Cryptography
Weight | 5 |
---|---|
Description | Candidates should understand X.509 certificates and public key infrastructures. They should also know how to configure and use OpenSSL to create certification authorities, and issue SSL certificates for various purposes. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 4 |
---|---|
Description | Candidates should know how to use X.509 certificates for both server and client authentication. They should be able to implement user and server authentication for Apache HTTPD.The version of Apache HTTPD covered is 2.4 or higher. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 3 |
---|---|
Description | Candidates should be able to configure encrypted file systems. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 5 |
---|---|
Description | Candidates should have experience and knowledge of cryptography in the context of DNS and its implementation using BIND. The version of BIND covered is 9.7 or higher. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Topic 326: Host Security
Weight | 3 |
---|---|
Description | Candidates should be able to secure computers running Linux against common threats. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 4 |
---|---|
Description | Candidates should be familiar with the use and configuration of common host intrusion detection software. This includes updates and maintenance as well as automated host scans. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 5 |
---|---|
Description | Candidates should be familiar with management and authentication of user accounts. This includes configuration and use of NSS, PAM, SSSD and Kerberos for both local and remote directories and authentication mechanisms as well as enforcing a password policy. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 4 |
---|---|
Description | Candidates should be familiar with FreeIPA v4.x. This includes installation and maintenance of a server instance with a FreeIPA domain as well as integration of FreeIPA with Active Directory. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Topic 327: Access Control
Weight | 3 |
---|---|
Description | Candidates are required to understand Discretionary Access Control and know how to implement it using Access Control Lists. Additionally, they are required to understand how to use Extended Attributes. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 4 |
---|---|
Description | Candidates should be familiar with Mandatory Access Control systems for Linux. Specifically, they should have a thorough understanding of SELinux. Also, they should be aware of other Mandatory Access Control for Linux. This includes major features of these systems but not configuration and use. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 3 |
---|---|
Description | Candidates should have experience and knowledge of security issues in use and configuration of NFSv4 clients and servers as well as CIFS client services. Knowledge of earlier versions of NFS is not required. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Topic 328: Network Security
Weight | 4 |
---|---|
Description | Candidates should be able to secure networks against common threats. This includes verification of the effectiveness of security measures. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 4 |
---|---|
Description | Candidates should be familiar with the use and configuration of network security scanning, network monitoring and network intrusion detection software. This includes updating and maintaining the security scanners. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 5 |
---|---|
Description | Candidates should be familiar with the use and configuration of packet filters. This includes netfilter, iptables, and ip6tables as well as nftables, nft, and ebtables. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|
Weight | 4 |
---|---|
Description | Candidates should be proficient in the use of OpenVPN and IPsec. |
Scope of Key Knowledge |
|
Important files, terms, and utilities: |
|