Domain 3 capstone: harden a server end to end and prove each control
Task
Take lin-b from a default installation to a hardened server, and prove every control rather than assert it: least-privilege accounts, key-and-code SSH through the jump box, a default-deny firewall, patches applied, unneeded services gone, encryption on its data volume, logs forwarded to the collector, and file integrity monitoring that catches an unauthorised change. The deliverable is a hardening record another administrator could audit.
Steps
- Revert lin-b to its clean baseline, then capture its starting state:
ss -tulpn, a full-range nmap scan from lin-srv, pending updates, and a Lynis hardening index. Save them underlab/capstone3/before/. - Apply the controls from this domain: patches; unneeded services removed; default-deny firewall allowing SSH from the jump box only; SSH keys plus one-time codes, no root login; an admin group with sudo and no shared accounts; a LUKS-encrypted data volume with an escrowed recovery key; and auth logs forwarded to lin-srv.
- Initialise AIDE's database, then change
/etc/hostsand add a file to/usr/local/bin. Runaide --checkand save the output tolab/capstone3/aide.txt. - Capture the same state as in step 1 under
lab/capstone3/after/. - Write
lab/capstone3/record.csvwith headercontrol,how_applied,evidence_file,test,result, where result ispassorfail, one row per control, each with the test that proves it and the file that shows the result, named relative tolab/capstone3/(for exampleafter/nmap.txt).
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -c 'open' lab/capstone3/before/*nmap* ; grep -c 'open' lab/capstone3/after/*nmap*
grep -hEi 'Hardening index' lab/capstone3/before/* lab/capstone3/after/*
grep -Eic '/etc/hosts' lab/capstone3/aide.txt
grep -Eic 'added|/usr/local/bin' lab/capstone3/aide.txt
awk -F, 'NR>1 {n++; if ($5!="pass") f++} END {print n" control(s), "f+0" not passing"}' lab/capstone3/record.csv
awk -F, 'NR>1 {print $3}' lab/capstone3/record.csv | while read f; do test -s "lab/capstone3/$f" || echo "missing evidence: $f"; done
Fewer open ports after than before, a higher hardening index, and AIDE reporting both the changed file and the added one. The record has at least eight controls, all passing, and every evidence file it names exists and is not empty -- a control whose evidence is missing is a control nobody can audit.
Notes
Hardening decays. Every package installed later, every firewall exception added under pressure, moves the server away from this record. Re-running the captures and comparing them with this capstone's output is the drift check the documentation lesson built.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.