Harden VM security
Apply patching, identity, and network controls to reduce risk.
- Build a practical VM hardening checklist.
VM security is layered: hardened base images, timely patching, least-privilege identity, host firewall rules, endpoint telemetry, and backup/restore testing. Disable unnecessary services, rotate secrets, and enforce MFA for privileged access. Security is not a one-time setup; it is continuous operations.
1checks = {
2 "patched": True,
3 "mfa_admin": True,
4 "unused_ports_closed": False,
5 "backups_tested": True
6}
7score = sum(1 for value in checks.values() if value)
8print(score)
9print("pass" if score >= 3 else "fail")3 pass
Defense-in-depth assumes one control can fail. Combine preventive controls (hardening), detective controls (monitoring), and corrective controls (rollback and recovery). Practice restores: an untested backup is just hope with storage costs.
Key takeaways
Build a practical VM hardening checklist.
VMs are powerful when automation and guardrails stay strong.
Observe before scaling; recover before incidents become outages.
Lesson quiz
5 questions · pass with 4 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Practice: write Python
Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.
Evaluate hardening status
Read four integers (0 or 1) for controls: patched, MFA, closed ports, tested backups. Print secure if at least 3 controls are enabled; otherwise print review.
- good posture
- needs work
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…