All certifications / Linux+ / Lessons
Linux+ XK0-006 lessons
Study Linux+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Linux+ study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: System management
- Boot process: UEFI/BIOS, GRUB2, kernel, initramfs (dracut, mkinitramfs), systemd targets
- Filesystem Hierarchy Standard: /etc, /var, /usr, /opt, /home, /boot, /proc, /sys, /dev
- Kernel modules and parameters: lsmod, modprobe, modinfo, /etc/modprobe.d, sysctl
- Files and directories: ls, find, cp, mv, hard vs symbolic links, file, stat
- Storage: partitions (fdisk, gdisk, parted), lsblk, blkid, UUIDs, /etc/fstab options (nofail, noexec)
- LVM (pvcreate, vgextend, lvextend -r) and software RAID with mdadm
- Filesystems: ext4, XFS, Btrfs; mkfs, mount, resize2fs, xfs_growfs; df and du
- Network configuration: ip, nmcli, netplan, hostnamectl, /etc/hosts, /etc/resolv.conf, nsswitch.conf
- Shell operations: redirection, pipes, environment variables, grep, sed, awk, cut, sort, uniq, tr
- Backup and restore: tar, gzip/xz/bzip2, rsync, dd, cpio
- Virtualization: KVM/QEMU, libvirt and virsh, virt-install, qcow2 vs raw images
Domain 2: Services and user management
- Local accounts and groups: useradd, usermod -aG, userdel, groupadd, passwd, chage
- Account files: /etc/passwd, /etc/shadow, /etc/group, /etc/skel, /etc/login.defs
- Systemd units: systemctl start/stop/enable/mask, status output, drop-in overrides with systemctl edit
- Scheduling: cron and crontab syntax, at, systemd timers (OnCalendar)
- Processes and jobs: ps, top, kill signals, nice/renice, bg/fg/jobs, nohup
- Package management: dnf/rpm, apt/dpkg, repositories, provides and file ownership queries
- Source and language packages: make, pip, sandboxed packages (Flatpak, Snap)
- Containers: podman/docker run, images, port publishing, volumes, logs, inspect
- Container orchestration concepts: Kubernetes pods, deployments, services
- Logging: journalctl filters, rsyslog, logrotate
Domain 3: Security
- Permissions: chmod symbolic and octal, chown, umask
- Special permissions: SUID, SGID, sticky bit; ACLs with setfacl and getfacl
- SELinux: modes, contexts, restorecon, semanage, booleans, ausearch; AppArmor profiles and modes
- Firewalls: firewalld zones and --permanent, ufw, nftables/iptables basics
- SSH hardening: key-based auth, ssh-copy-id, sshd_config (PermitRootLogin, PasswordAuthentication)
- Privilege escalation: sudo, visudo, /etc/sudoers.d, su, polkit
- Authentication: PAM modules (pam_faillock, pam_pwquality), LDAP/SSSD, Kerberos, MFA
- Cryptography: hashing (sha256sum), GPG signatures, TLS certificates, LUKS disk encryption
- OS hardening: disabling unused services, secure boot, patching, file integrity (AIDE)
- Compliance and auditing: auditd, log review, vulnerability scanning, CIS benchmarks
Domain 4: Automation, orchestration, and scripting
- Bash scripting: shebang, variables, parameter expansion, quoting, exit codes and $?
- Bash control flow: if/test, case, for and while loops, functions, arrays
- Safer scripts: set -euo pipefail, trap, input validation, shellcheck
- Python basics for admins: data types, sets and dicts, venv, pip, running scripts
- Git: clone, branch/switch, add, commit, merge, rebase, revert, pull requests
- Ansible: inventory, ad hoc commands, playbooks, idempotence, roles, ansible-vault
- Puppet and other agent-based tools; OpenTofu/Terraform plan and apply
- CI/CD pipelines and GitOps concepts
- Responsible use of AI tools for scripting: review, testing, keeping secrets out of prompts
Domain 5: Troubleshooting
- Storage issues: full disks, inode exhaustion (df -i), deleted-but-open files (lsof +L1), fsck/xfs_repair
- Performance: load average, top/htop, vmstat, iostat, sar, free, OOM killer
- Networking: ping, ip route, ss, dig/resolvectl, traceroute/tracepath/mtr, tcpdump, nmap
- Boot problems: GRUB menu, previous kernels, emergency and rescue targets, fstab errors
- Service failures: systemctl status exit codes, journalctl, dependencies, port conflicts
- Security issues: SELinux denials, file permissions, SSH key permissions, locked accounts
- Hardware: dmesg, lspci, lsusb, smartctl, failing disks and RAID degradation
- Time sync: chrony, timedatectl, clock skew effects on TLS and Kerberos
- Package problems: broken dependencies, repository errors, held packages
- Container problems: logs, port conflicts, image pulls, storage