Overview
What this challenge is about.
Inventory setuid/setgid binaries on a Linux distro, classify risks, and propose eight hardening changes. Earn a verifiable certificate.
The scenario
The bank (regulated by MAS, just completed PCI-DSS recertification) wants to harden the base image before the next 2-year refresh — every setuid binary is an attack-surface decision.
The Brief
What you'll do, and what you'll demonstrate.
Audit all setuid binaries in a Linux base image, classify by risk, and produce a 90-day hardening roadmap a CISO can fund.
Earning criteria — what you'll demonstrate
- Understand the Linux setuid model and its historical attack patterns
- Use file capabilities (cap_set_file) as a least-privilege alternative to setuid
- Classify OS-level risk in terms a security leader can fund
- Write security recommendations that respect operational reality
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Os Security
Apply os security to solve real industry problems and demonstrate production-level capability.
- Linux Administration
Apply linux administration to solve real industry problems and demonstrate production-level capability.
- Setuid Analysis
Apply setuid analysis to solve real industry problems and demonstrate production-level capability.
- Capabilities
Apply capabilities to solve real industry problems and demonstrate production-level capability.
- Risk Classification
Apply risk classification to solve real industry problems and demonstrate production-level capability.
- Audit
Apply audit to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles: