LPI LPIC-3 Exam Summary:
Exam Name | LPIC-3 Security |
Exam Code | 303-200 |
Exam Price | $200 (USD) |
Duration | 90 Mins |
Number of Questions | 60 |
Passing Score | 500 / 800 |
Sample Questions | LPI LPIC-3 Sample Questions |
Practice Exam | LPI 303-200 Certification Practice Exam |
LPI 303-200 Exam Syllabus Topics:
Topic | Details |
Cryptography | |
325.1 X.509 Certificates and Public Key Infrastructures |
Weight: 5 Description: Candidates should understand X.509 certificates and public key infrastructures. They should know how to configure and use OpenSSL to implement certification authorities and issue SSL certificates for various purposes. Key Knowledge Areas: ◉ Understand X.509 certificates, X.509 certificate lifecycle, X.509 certificate fields and X.509v3 certificate extensions The following is a partial list of the used files, terms and utilities: ◉ openssl, including relevant subcommands |
325.2 X.509 Certificates for Encryption, Signing and Authentication |
Weight: 4 Description: Candidates should know how to use X.509 certificates for both server and client authentication. Candidates should be able to implement user and server authentication for Apache HTTPD. The version of Apache HTTPD covered is 2.4 or higher. Key Knowledge Areas: ◉ Understand SSL, TLS and protocol versions Terms and Utilities: ◉ Intermediate certification authorities |
325.3 Encrypted File Systems |
Weight: 3 Description: Candidates should be able to setup and configure encrypted file systems. Key Knowledge Areas: ◉ Understand block device and file system encryption Terms and Utilities: ◉ cryptsetup |
325.4 DNS and Cryptography |
Weight: 5 Description: Candidates should have experience and knowledge of cryptography in the context of DNS and its implementation using BIND. The version of BIND covered is 9.7 or higher. Key Knowledge Areas: ◉ Understanding of DNSSEC and DANE Terms and Utilities: ◉ DNS, EDNS, Zones, Resource Records |
Host Security | |
Host Hardening |
Weight: 3 Description: Candidates should be able to secure computers running Linux against common threats. This includes kernel and software configuration. Key Knowledge Areas: ◉ Configure BIOS and boot loader (GRUB 2) security Terms and Utilities: ◉ grub.cfg |
Host Intrusion Detection |
Weight: 4 Description: Candidates should be familiar with the use and configuration of common host intrusion detection software. This includes updates and maintenance as well as automated host scans. Key Knowledge Areas: ◉ Use and configure the Linux Audit system Terms and Utilities: ◉ auditd |
User Management and Authentication |
Weight: 5 Description: Candidates should be familiar with management and authentication of user accounts. This includes configuration and use of NSS, PAM, SSSD and Kerberos for both local and remote directories and authentication mechanisms as well as enforcing a password policy. Key Knowledge Areas: ◉ Understand and configure NSS Terms and Utilities: ◉ nsswitch.conf |
FreeIPA Installation and Samba Integration |
Weight: 4 Description: Candidates should be familiar with FreeIPA v4.x. This includes installation and maintenance of a server instance with a FreeIPA domain as well as integration of FreeIPA with Active Directory. Key Knowledge Areas: ◉ Understand FreeIPA, including its architecture and components Terms and Utilities: ◉ 389 Directory Server, MIT Kerberos, Dogtag Certificate System, NTP, DNS, SSSD, certmonger |
Access Control | |
Discretionary Access Control |
Weight: 3 Description: Candidates are required to understand Discretionary Access Control and know how to implement it using Access Control Lists. Additionally, candidates are required to understand and know how to use Extended Attributes. Key Knowledge Areas: ◉ Understand and manage file ownership and permissions, including SUID and SGID Terms and Utilities: ◉ getfacl |
Mandatory Access Control |
Weight: 4 Description: Candidates should be familiar with Mandatory Access Control systems for Linux. Specifically, candidates should have a thorough knowledge of SELinux. Also, candidates should be aware of other Mandatory Access Control systems for Linux. This includes major features of these systems but not configuration and use. Key Knowledge Areas: ◉ Understand the concepts of TE, RBAC, MAC and DAC Terms and Utilities: ◉ getenforce, setenforce, selinuxenabled |
Network File Systems |
Weight: 3 Description: Candidates should have experience and knowledge of security issues in use and configuration of NFSv4 clients and servers as well as CIFS client services. Earlier versions of NFS are not required knowledge. Key Knowledge Areas: ◉ Understand NFSv4 security issues and improvements Terms and Utilities: ◉ /etc/exports |
Network Security | |
Network Hardening |
Weight: 4 Description: Candidates should be able to secure networks against common threats. This includes verification of the effectiveness of security measures. Key Knowledge Areas: ◉ Configure FreeRADIUS to authenticate network nodes Terms and Utilities: ◉ radiusd |
Network Intrusion Detection |
Weight: 4 Description: Candidates should be familiar with the use and configuration of network security scanning, network monitoring and network intrusion detection software. This includes updating and maintaining the security scanners. Key Knowledge Areas: ◉ Implement bandwidth usage monitoring Terms and Utilities: ◉ ntop |
Packet Filtering |
Weight: 5 Description: Candidates should be familiar with the use and configuration of packet filters. This includes netfilter, iptables and ip6tables as well as basic knowledge of nftables, nft and ebtables. Key Knowledge Areas: ◉ Understand common firewall architectures, including DMZ Terms and Utilities: ◉ iptables |
Virtual Private Networks |
Weight: 4 Description: Candidates should be familiar with the use of OpenVPN and IPsec. Key Knowledge Areas: ◉ Configure and operate OpenVPN server and clients for both bridged and routed VPN networks Terms and Utilities: ◉ /etc/openvpn/* |
0 comments:
Post a Comment