Linux LPIC-3 303 Security | 303 Exam Preparation

€850.00
| /

________________________________________________________________

Do you want to take this course in another training mode?
Contact us

Other modes: Telepresence - Classroom

________________________________________________________________

ATTENTION: If you belong to the LaaS Cert program, the training does not include an exam

LPIC-3 Security Official Certification Course

LPIC‑3 Security certification

What is LPIC‑3 Enterprise Professional Security?

This certification is the expert level of the Linux Professional Institute (LPI) certification program, aimed at professionals who manage Linux systems in enterprise environments with an advanced focus on security.

The LPIC-3 303 exam validates competencies in encryption, host security, access control, network security, firewalls, and VPNs on Linux, making it one of the most internationally recognized certifications.

This course covers the syllabus for preparing for exam 303, which is necessary to become LPIC-3 certified. The training is delivered virtually and can be purchased with or without a certification exam voucher; it is also 100% eligible for corporate training subsidies. (Consult for other training options).

With this course, you will become an expert in Linux security and earn a high-level international professional certification!

 

 

What are the benefits of obtaining the LPIC-3 Security certification?

Obtaining the LPIC‑3 Security certification allows you to:

  • Accredit expert knowledge in enterprise Linux security
  • Specialize in encryption, access control, and network security
  • Improve your professional profile in cybersecurity areas
  • Access high-level technical roles and increase employability
  • Obtain international recognition

 

What are the prerequisites for LPIC-3?

To take the course and qualify for the certification, it is necessary to:

  • Have an active LPIC‑2 as a prerequisite to obtain LPIC-3.
  • Have experience in advanced system administration
  • Prior knowledge of networks, users, permissions, and services

 

Nanfor, a customized ICT training center authorized by the Linux Professional Institute

Nanfor is an official center designated as a Platinum partner and offers all official Linux LPI courses. It is accredited by LPI as a Training Partner and Channel Partner, which reinforces the course's alignment with official standards. 

 

⏱️

Course duration:
165 hours

💻

Modality and Support:
Virtual, support always by your side

🔑

Classroom access:
3 months

Who is the LPIC‑3 Security course for?

This LPIC-3 course is aimed at professionals who wish to become:

  • Linux system administrators with advanced experience
  • Cybersecurity professionals in Linux environments
  • System and network engineers
  • IT consultants specializing in infrastructure
  • Professionals who already have their LPIC‑2 and wish to reach the expert level

It is especially recommended for those working in enterprise security, access management, data protection, and critical environments.

 

LPIC-3 Security Course Content

Here you will find the complete structure of the training program, with key points and the practical focus of the training.

Topic 331: Cryptography

331.1 X.509 Certificates and Public Key Infrastructures

Candidates must understand X.509 certificates and public key infrastructures. They must know how to configure and use OpenSSL to implement certificate authorities and issue SSL certificates for various purposes.

Key areas of knowledge:

  • Understand X.509 certificates, X.509 certificate lifecycles, X.509 certificate fields, and X.509v3 certificate extensions.
  • Understand chains of trust and public key infrastructures, including certificate transparency.
  • Generate and manage public and private keys
  • Create, operate, and secure a certificate authority
  • Request, sign, and manage server and client certificates
  • Revoke certificates and certificate authorities
  • Knowledge of the basic functions of Let's Encrypt, ACME, and certbot
  • Knowledge of the basic features of CFSSL

331.2 X.509 Certificates for Encryption, Signing, and Authentication

Candidates must be able to use X.509 certificates for both server and client authentication. This includes implementing user and server authentication for Apache HTTPD. The version of Apache HTTPD covered is 2.4 or higher.

Key areas of knowledge:

  • Understand SSL, TLS, including protocol versions and ciphers.
  • Configure Apache HTTPD with mod_ssl to provide HTTPS service, including SNI and HSTS
  • Configure Apache HTTPD with mod_ssl to serve certificate chains and adjust cipher settings (without specific cipher knowledge)
  • Configure Apache HTTPD with mod_ssl to authenticate users using certificates
  • Configure Apache HTTPD with mod_ssl to provide OCSP stapling
  • Use OpenSSL for SSL/TLS client and server testing

331.3 File Encryption Systems

Candidates must be able to install and configure file encryption systems.

Key areas of knowledge:

  • Understand block device and file system encryption
  • Use dm-crypt with LUKS1 to encrypt block devices
  • Use eCryptfs to encrypt file systems, including home directories and PAM integration
  • Awareness of simple dm-crypt
  • Knowledge of LUKS2 features
  • Conceptual compression of the keyslot for LUKS devices and keyslot PINs for TMP2 and Network Bound Disk Encryption (NBDE)/Tang

331.4 DNS and Cryptography

Candidates must have experience and knowledge of cryptography in the context of DNS and its implementation using BIND. The version of BIND covered is 9.7 or higher.

Key areas of knowledge:

  • Understand the concepts of DNS, zones, and resource records.
  • Understand DNSSEC, including Key Signing Keys (KSK), Zone Signing Keys (ZSK), and relevant DNS records such as DS, DNSKEY, RRSIG, NSEC, NSEC3, and NSEC3PARAM.
  • Configure and troubleshoot BIND as an authoritative name server serving DNSSEC-protected zones
  • Manage DNSSEC-signed zones, including key generation, key rollover, and zone re-signing
  • Configure BIND as a recursive name server that performs DNSSEC validation on behalf of its clients
  • Understand CAA and DANE, including relevant DNS records such as CAA and TLSA
  • Use CAA and DANE to publish X.509 certificate and certificate authority information in DNS
  • Use TSIG for secure communication with BIND.
  • Knowledge of DNS over TLS and DNS over HTTPS.
  • Knowledge of Multicast DNS

Topic 332: Host Security

332.1 Host Hardening

Candidates must be able to protect computers running Linux against common threats.

Key areas of knowledge:

  • Configure BIOS and bootloader (GRUB 2) security
  • Disable unused software and services
  • Understand and remove unnecessary capabilities for specific systemd units and for the entire system
  • Understand and configure Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Exec-Shield
  • Whitelist and blacklist USB devices connected to a computer using USBGuard
  • Create an SSH CA, create SSH certificates for host and user keys using the CA, and configure OpenSSH to use SSH certificates
  • Work with chroot environments
  • Use systemd units to limit system calls and capabilities available to a process
  • Use systemd units to start processes with limited or no access to specific files and devices
  • Use systemd units to start processes with dedicated temporary and /dev directories and no network access
  • Understand the implications of Linux Meltdown and Spectre mitigations and enable/disable the mitigations
  • Polkit awareness
  • Awareness of the security advantages of virtualization and containerization

332.2 Host Intrusion Detection

Candidates should be familiar with the use and configuration of common host intrusion detection software. This includes audit system management and system integrity verification.

Key Knowledge Areas:

  • Use and configure the audit system
  • Use chrootkit
  • Use and configure rkhunter, including updates
  • Use Linux Malware Detect
  • Automate host scans using cron
  • Use RPM and DPKG package management tools to verify the integrity of installed files, especially in enterprise security v3.0 environments.
  • Configure and use AIDE, including rule management
  • OpenSCAP awareness

332.3 Resource Control

Candidates should be able to restrict the resources that services and programs can consume.

Key Knowledge Areas:

  • Understand and configure ulimits
  • Understand cgroups, including classes, limits, and accounting
  • Manage cgroups and process cgroup association
  • Understand systemd slices, scopes, and services
  • Use systemd units to limit the system resources that processes can consume
  • Knowledge of cgmanager and libcgroup utilities

Topic 333: Access Control

333.1 Discretionary Access Control

Candidates should understand Discretionary Access Control (DAC) and know how to implement it using Access Control Lists (ACLs). Additionally, they should understand and know how to use extended attributes.

Key Knowledge Areas:

  • Understand and manage file ownership and permissions, including SetUID and SetGID bits
  • Understand and manage access control lists
  • Understand and manage extended attributes and attribute classes

333.2 Mandatory Access Control

Candidates should be familiar with Mandatory Access Control (MAC) systems for Linux. Specifically, they must have in-depth knowledge of SELinux. Likewise, they should be aware of other mandatory access control systems for Linux. This includes the main features of these systems, but not their configuration or use.

Key Knowledge Areas:

  • Understand the concepts of type enforcement, role-based access control, mandatory access control, and discretionary access control.
  • Configure, manage, and use SELinux
  • Knowledge of AppArmor and Smack

Topic 334: Network Security

334.1 Network Hardening

Candidates should be able to protect networks against common threats. This includes analyzing network traffic for specific nodes and protocols, which is vital for Linux professionals.

Key Knowledge Areas:

  • Understand wireless network security mechanisms
  • Configure FreeRADIUS to authenticate network nodes
  • Use Wireshark and tcpdump to analyze network traffic, including filters and statistics
  • Use Kismet to analyze wireless networks and capture wireless network traffic
  • Identify and address rogue router advertisements and DHCP messages
  • Awareness of aircrack-ng and bettercap

334.2 Network Intrusion Detection, an essential component for LPIC-3 certification.

Candidates should be familiar with the use and configuration of network intrusion detection, monitoring, and scanning software. This includes updating and maintaining security scanners.

Key Knowledge Areas:

  • Implement bandwidth usage monitoring
  • Configure and use Snort, including rule management
  • Configure and use OpenVAS, including NASL

334.3 Packet Filtering

Candidates should be familiar with the use and configuration of the Linux netfilter packet filter.

Key Knowledge Areas:

  • Understand common firewall architectures, including DMZ
  • Understand and use iptables and ip6tables, including standard modules, tests, and targets
  • Implement packet filtering for IPv4 and IPv6
  • Implement connection tracking and network address translation
  • Manage IP sets and use them in netfilter rules
  • Awareness of nftables and NFT
  • Awareness of debits
  • Awareness of control

334.4 Virtual Private Networks

Candidates should be familiar with using OpenVPN, IPsec, and WireGuard to configure remote access and site-to-site VPNs.

Key Knowledge Areas:

  • Understand the principles of routed and bridged VPNs
  • Understand the principles and main differences of the OpenVPN, IPsec, IKEv2, and WireGuard protocols
  • Configure and operate OpenVPN servers and clients
  • Configure and operate IPsec servers and clients using strongSwan
  • Configure and operate WireGuard servers and clients
  • Awareness of L2TP

Topic 335: Threats and Vulnerability Assessment

335.1 Common security vulnerabilities and threats in enterprise environments.

Candidates should understand the principle of the main types of security vulnerabilities and threats.

Key Knowledge Areas:

  • Conceptual understanding of threats against individual nodes
  • Conceptual understanding of threats to networks
  • Conceptual understanding of threats to applications
  • Conceptual understanding of threats against credentials and confidentiality
  • Conceptual understanding of honeypots

335.2 Penetration Testing

Candidates understand the concepts of penetration testing, including knowledge of commonly used tools. In addition, they must be able to use nmap to verify the effectiveness of network security measures.

Key Knowledge Areas:

  • Understand the concepts of penetration testing and ethical hacking
  • Understand the legal implications of penetration testing
  • Understand the phases of penetration testing, such as active and passive information gathering, enumeration, gaining access, privilege escalation, maintaining access, and covering tracks.
  • Understand the Metasploit architecture and components, including types of Metasploit modules and how Metasploit integrates various security tools
  • Use nmap to scan networks and hosts, including different scan methods, version scans, and OS fingerprinting
  • Understand the concepts of Nmap Scripting Engine and run existing scripts
  • Knowledge of Kali Linux, Armitage, and the Social Engineering Toolkit (SET)

 

Course and exam language

  • The e-Learning components used for the training are available in English and Spanish.
  • Exam languages available at Pearson Vue test centers: English, Japanese
  • Exam languages available online via OnVUE: English, Japanese

 

Interested in taking this course? Request information now

If you want to take this course virtually, you can purchase it at the top of the product page. If you have any questions, please contact us.

If you want to take this course in an in-person or live online (telepresence) format, please contact us:

 

Frequently Asked Questions

Check out quick answers regarding the training and recommendations for planning your preparation path.

1) What is LPIC‑3 Security?

LPIC‑3 303 is LPI's expert-level specialty focused on Linux security. It validates advanced competencies in encryption, access control, network security, firewalls, and VPNs, oriented toward enterprise environments.

2) Does this course specifically prepare for the LPIC‑3 303 exam?

Yes. The course is designed to cover the necessary syllabus for exam preparation and is geared toward obtaining the certification.

3) What topics does the LPIC‑3 Security exam cover?

The exam evaluates advanced areas such as encryption, host security, access control, network security, and firewall and VPN configuration.

4) How long is the course and how much time do I have access to the classroom?

The course description indicates a duration of 165 hours and 3 months of access to the online classroom. It can be taken in other formats upon request.

5) Does it include an official exam? What if I am in LaaS Cert?

The description states that if you belong to the LaaS Cert program, the training is provided without the exam included.

6) Is Nanfor an official LPI partner for this training?

Nanfor is an authorized LPI center, being a Platinum partner accredited by LPI as a Training Partner and Channel Partner, which reinforces the course's alignment with official standards.

7) Which professional profile benefits most from this accreditation?

It is especially recommended for professionals who administer Linux in organizations and want to specialize in advanced security, reinforcing their profile for senior administration and security roles.

8) What security certifications exist?

In the Linux field, the most specialized accreditation in security is LPIC‑3 Security, oriented toward secure Linux system administration in enterprise environments.

In addition, there are complementary accreditations such as LPIC‑2, RHCE, CEH, or Security+, which are widely used when Linux is the base operating system.

9) How much do LPI exams cost?

Exam prices are regional and may vary by country. For Spain, Nanfor offers the purchase of official LPI certification vouchers, where you can check the updated price for each type of exam (LPIC‑1, LPIC‑2, LPIC‑3, Essentials, etc.) at the following link: 👉 https://nanfor.com/collections/examen-oficial-linux/products/examen-oficial-linux

10) What prior knowledge is recommended for taking the LPIC‑3 303 Security course?

LPIC‑3 303 Security is aimed at professionals with prior experience in Linux administration. It is usually recommended to have knowledge equivalent to LPIC‑2 or practical experience managing Linux systems, networks, and enterprise services.

💡 Did you know this course is included in LaaS Cert?

Take this course and many more with our LaaS Cert annual license . Unlimited training for only €1,295!

✅ Microsoft, Linux-LPI, SCRUM, ITIL and Nanfor technical courses

✅ Personalized support always by your side

✅ 100% online, official and updated

Get your license now!

LaaS cert Formación ilimitada

Information related to training

Soporte siempre a tu lado

Training support

Always by your side

Modalidades Formativas

Training modalities

Self Learning - Virtual - In-person - Telepresence

bonificaciones

Bonuses

For companies