
LPIC-3 Security
The LPIC-3 Security certification validates your ability to secure and harden Linux-based servers, services, and networks enterprise-wide. It is designed for senior Linux professionals who are responsible for implementing robust security measures across complex environments. Earning this credential demonstrates advanced expertise in cryptography, host security, access control, and network security, positioning you as a trusted security specialist in the open source ecosystem.
459 practice questions · Updated 2026-07-30
LPIC-3-SECURITY Curriculum
Every domain, objective, and concept the LPIC-3-SECURITY exam measures.
- X.509 certificate structure
- X.509v3 extensions
- X.509 certificate lifecycle
- Trust chains and PKI
- Key pair generation
- Private key management
- Setting up a certification authority
- Securing a certification authority
- Certificate signing requests
- Certificate issuance and management
- Server and client certificates
- Certificate revocation
- SSL/TLS protocol fundamentals
- TLS protocol versions and security
- Common TLS threats
- Apache mod_ssl configuration for HTTPS
- Server Name Indication (SNI)
- HTTP Strict Transport Security (HSTS)
- Client certificate authentication
- OCSP stapling
- OpenSSL client and server testing
- Block device vs. file system encryption
- dm-crypt and LUKS fundamentals
- Creating and managing LUKS encrypted devices
- eCryptfs fundamentals
- Encrypting home directories with eCryptfs and PAM integration
- Plain dm-crypt and EncFS awareness
- DNSSEC Fundamentals
- DANE Fundamentals
- BIND DNSSEC Zone Configuration
- DNSSEC Key Generation and Management
- Zone Signing and Re-signing
- DNSSEC Validation with BIND
- DNSSEC Troubleshooting
- DANE Record Configuration
- TSIG for Secure BIND Communication
- BIOS Security Configuration
- GRUB 2 Boot Loader Security
- Disabling Unnecessary Services
- Kernel Security with sysctl
- Resource Usage Limitation
- Chroot Environment Management
- Capability Dropping
- Virtualization Security Advantages
- Linux Audit system basics
- Configuring audit rules
- Analyzing audit logs
- chkrootkit usage
- rkhunter configuration and updates
- Linux Malware Detect (LMD) usage
- Automating host scans with cron
- AIDE installation and initialization
- AIDE rule management
- AIDE database updates and verification
- OpenSCAP awareness
- NSS Overview
- NSS Configuration Files
- NSS Modules
- PAM Overview
- PAM Configuration Files
- PAM Module Types and Controls
- Common PAM Modules
- Password Complexity Policies
- Periodic Password Changes
- Account Lockout After Failed Attempts
- SSSD Overview
- SSSD Configuration
- SSSD Domains and Providers
- Integrating SSSD with NSS
- Integrating SSSD with PAM
- SSSD with Active Directory
- SSSD with IPA
- SSSD with LDAP
- SSSD with Kerberos
- SSSD with Local Domains
- Kerberos Basics
- Kerberos Client Configuration
- Obtaining Kerberos Tickets
- Managing Kerberos Tickets
- FreeIPA architecture and components
- FreeIPA system and configuration prerequisites
- FreeIPA server installation
- FreeIPA domain management
- Active Directory replication and trust configuration
- FreeIPA sudo integration
- FreeIPA autofs integration
- FreeIPA SSH integration
- FreeIPA SELinux integration
- File ownership and permissions
- SUID and SGID special permissions
- Access control lists (ACLs)
- Extended attributes
- Attribute classes
- TE (Type Enforcement)
- RBAC (Role-Based Access Control)
- MAC (Mandatory Access Control)
- DAC (Discretionary Access Control)
- SELinux Modes
- SELinux Policies
- SELinux Contexts
- SELinux Booleans
- SELinux File and Process Management
- SELinux Troubleshooting
- AppArmor Overview
- AppArmor Configuration
- Smack Overview
- Smack Configuration
- NFSv4 Security Issues and Improvements
- NFSv4 Server Configuration
- NFSv4 Client Configuration
- NFSv4 Authentication Mechanisms
- NFSv4 Pseudo File System
- NFSv4 ACLs
- CIFS Client Configuration
- CIFS Unix Extensions
- CIFS Security Modes
- CIFS ACLs and SIDs Mapping
- FreeRADIUS basics
- FreeRADIUS client configuration
- FreeRADIUS authentication methods
- FreeRADIUS user database integration
- FreeRADIUS testing and debugging
- nmap scan types
- nmap host discovery
- nmap port scanning
- nmap OS and version detection
- nmap scripting engine
- Wireshark capture and display filters
- Wireshark statistics tools
- Wireshark packet analysis
- Rogue router advertisement detection
- Rogue DHCP message detection
- Mitigation of rogue network devices
- Bandwidth monitoring fundamentals
- Bandwidth monitoring tools
- Snort installation and configuration
- Snort rule syntax and management
- Snort operation and alerting
- OpenVAS installation and configuration
- OpenVAS scanning and reporting
- NASL scripting basics
- Firewall architectures and DMZ
- netfilter and iptables basics
- iptables tables, chains, and rules
- Standard iptables modules, tests, and targets
- IPv4 and IPv6 packet filtering
- Connection tracking
- Network address translation (NAT)
- IP sets
- nftables and nft basics
- ebtables basics
- conntrackd awareness
- OpenVPN fundamentals
- OpenVPN server configuration
- OpenVPN client configuration
- Bridged VPN with OpenVPN
- Routed VPN with OpenVPN
- OpenVPN operation and maintenance
- IPsec fundamentals
- IPsec-Tools and racoon configuration
- IPsec server configuration
- IPsec client configuration
- IPsec operation and troubleshooting
- L2TP awareness
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for LPIC-3-SECURITY, so none is invented.