Book Image

Hands-On Enterprise Automation on Linux

By : James Freeman
Book Image

Hands-On Enterprise Automation on Linux

By: James Freeman

Overview of this book

Automation is paramount if you want to run Linux in your enterprise effectively. It helps you minimize costs by reducing manual operations, ensuring compliance across data centers, and accelerating deployments for your cloud infrastructures. Complete with detailed explanations, practical examples, and self-assessment questions, this book will teach you how to manage your Linux estate and leverage Ansible to achieve effective levels of automation. You'll learn important concepts on standard operating environments that lend themselves to automation, and then build on this knowledge by applying Ansible to achieve standardization throughout your Linux environments. By the end of this Linux automation book, you'll be able to build, deploy, and manage an entire estate of Linux servers with higher reliability and lower overheads than ever before.
Table of Contents (23 chapters)
1
Section 1: Core Concepts
5
Section 2: Standardizing Your Linux Servers
10
Section 3: Day-to-Day Management
16
Section 4: Securing Your Linux Servers

Chapter 13 - Using CIS Benchmarks

  1. They provide a standardized, industry-agreed way to secure Linux servers.
  2. Yes, it does.
  3. A level 1 benchmark is not expected to have an impact on day-to-day operations of your server. A level 2 benchmark is and so should be implemented with care.
  4. Scored benchmarks are expected to be crucial to all systems, whereas benchmarks that are not scored are expected to be applied to only some systems (for example, wireless network adapter configuration hardening will only apply to a subset of machines—hence, this should not affect the score of all machines).
  5. This is normally provided in the benchmark document but often involves using the grep utility within the script to check for the configuration settings in a given file and reporting back on whether it was found or not.
  6. Possible answers include the following:
    • Pattern matching can be an imprecise...