Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
LINUX PROFESSIONAL INSTITUTE

LPIC-3 Security

LPIC-3-SECURITY

The LPIC-3 Security certification validates your ability to secure and harden Linux-based servers, services, and networks enterprise-wide. It is designed for senior Linux professionals who are responsible for implementing robust security measures across complex environments. Earning this credential demonstrates advanced expertise in cryptography, host security, access control, and network security, positioning you as a trusted security specialist in the open source ecosystem.

459 practice questions · Updated 2026-07-30

4Domains
15Objectives
164Concepts
459Questions

LPIC-3-SECURITY Curriculum

Every domain, objective, and concept the LPIC-3-SECURITY exam measures.

  1. X.509 certificate structure
  2. X.509v3 extensions
  3. X.509 certificate lifecycle
  4. Trust chains and PKI
  5. Key pair generation
  6. Private key management
  7. Setting up a certification authority
  8. Securing a certification authority
  9. Certificate signing requests
  10. Certificate issuance and management
  11. Server and client certificates
  12. Certificate revocation
  1. SSL/TLS protocol fundamentals
  2. TLS protocol versions and security
  3. Common TLS threats
  4. Apache mod_ssl configuration for HTTPS
  5. Server Name Indication (SNI)
  6. HTTP Strict Transport Security (HSTS)
  7. Client certificate authentication
  8. OCSP stapling
  9. OpenSSL client and server testing
  1. Block device vs. file system encryption
  2. dm-crypt and LUKS fundamentals
  3. Creating and managing LUKS encrypted devices
  4. eCryptfs fundamentals
  5. Encrypting home directories with eCryptfs and PAM integration
  6. Plain dm-crypt and EncFS awareness

325.4 DNS and Cryptography (weight: 5)

9 concepts · 30 questions
  1. DNSSEC Fundamentals
  2. DANE Fundamentals
  3. BIND DNSSEC Zone Configuration
  4. DNSSEC Key Generation and Management
  5. Zone Signing and Re-signing
  6. DNSSEC Validation with BIND
  7. DNSSEC Troubleshooting
  8. DANE Record Configuration
  9. TSIG for Secure BIND Communication

326.1 Host Hardening (weight: 3)

8 concepts · 26 questions
  1. BIOS Security Configuration
  2. GRUB 2 Boot Loader Security
  3. Disabling Unnecessary Services
  4. Kernel Security with sysctl
  5. Resource Usage Limitation
  6. Chroot Environment Management
  7. Capability Dropping
  8. Virtualization Security Advantages
  1. Linux Audit system basics
  2. Configuring audit rules
  3. Analyzing audit logs
  4. chkrootkit usage
  5. rkhunter configuration and updates
  6. Linux Malware Detect (LMD) usage
  7. Automating host scans with cron
  8. AIDE installation and initialization
  9. AIDE rule management
  10. AIDE database updates and verification
  11. OpenSCAP awareness
  1. NSS Overview
  2. NSS Configuration Files
  3. NSS Modules
  4. PAM Overview
  5. PAM Configuration Files
  6. PAM Module Types and Controls
  7. Common PAM Modules
  8. Password Complexity Policies
  9. Periodic Password Changes
  10. Account Lockout After Failed Attempts
  11. SSSD Overview
  12. SSSD Configuration
  13. SSSD Domains and Providers
  14. Integrating SSSD with NSS
  15. Integrating SSSD with PAM
  16. SSSD with Active Directory
  17. SSSD with IPA
  18. SSSD with LDAP
  19. SSSD with Kerberos
  20. SSSD with Local Domains
  21. Kerberos Basics
  22. Kerberos Client Configuration
  23. Obtaining Kerberos Tickets
  24. Managing Kerberos Tickets
  1. FreeIPA architecture and components
  2. FreeIPA system and configuration prerequisites
  3. FreeIPA server installation
  4. FreeIPA domain management
  5. Active Directory replication and trust configuration
  6. FreeIPA sudo integration
  7. FreeIPA autofs integration
  8. FreeIPA SSH integration
  9. FreeIPA SELinux integration

  1. File ownership and permissions
  2. SUID and SGID special permissions
  3. Access control lists (ACLs)
  4. Extended attributes
  5. Attribute classes
  1. TE (Type Enforcement)
  2. RBAC (Role-Based Access Control)
  3. MAC (Mandatory Access Control)
  4. DAC (Discretionary Access Control)
  5. SELinux Modes
  6. SELinux Policies
  7. SELinux Contexts
  8. SELinux Booleans
  9. SELinux File and Process Management
  10. SELinux Troubleshooting
  11. AppArmor Overview
  12. AppArmor Configuration
  13. Smack Overview
  14. Smack Configuration

327.3 Network File Systems (weight: 3)

10 concepts · 30 questions
  1. NFSv4 Security Issues and Improvements
  2. NFSv4 Server Configuration
  3. NFSv4 Client Configuration
  4. NFSv4 Authentication Mechanisms
  5. NFSv4 Pseudo File System
  6. NFSv4 ACLs
  7. CIFS Client Configuration
  8. CIFS Unix Extensions
  9. CIFS Security Modes
  10. CIFS ACLs and SIDs Mapping

328.1 Network Hardening (weight: 4)

16 concepts · 44 questions
  1. FreeRADIUS basics
  2. FreeRADIUS client configuration
  3. FreeRADIUS authentication methods
  4. FreeRADIUS user database integration
  5. FreeRADIUS testing and debugging
  6. nmap scan types
  7. nmap host discovery
  8. nmap port scanning
  9. nmap OS and version detection
  10. nmap scripting engine
  11. Wireshark capture and display filters
  12. Wireshark statistics tools
  13. Wireshark packet analysis
  14. Rogue router advertisement detection
  15. Rogue DHCP message detection
  16. Mitigation of rogue network devices
  1. Bandwidth monitoring fundamentals
  2. Bandwidth monitoring tools
  3. Snort installation and configuration
  4. Snort rule syntax and management
  5. Snort operation and alerting
  6. OpenVAS installation and configuration
  7. OpenVAS scanning and reporting
  8. NASL scripting basics

328.3 Packet Filtering (weight: 5)

11 concepts · 25 questions
  1. Firewall architectures and DMZ
  2. netfilter and iptables basics
  3. iptables tables, chains, and rules
  4. Standard iptables modules, tests, and targets
  5. IPv4 and IPv6 packet filtering
  6. Connection tracking
  7. Network address translation (NAT)
  8. IP sets
  9. nftables and nft basics
  10. ebtables basics
  11. conntrackd awareness
  1. OpenVPN fundamentals
  2. OpenVPN server configuration
  3. OpenVPN client configuration
  4. Bridged VPN with OpenVPN
  5. Routed VPN with OpenVPN
  6. OpenVPN operation and maintenance
  7. IPsec fundamentals
  8. IPsec-Tools and racoon configuration
  9. IPsec server configuration
  10. IPsec client configuration
  11. IPsec operation and troubleshooting
  12. L2TP awareness
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for LPIC-3-SECURITY, so none is invented.