Google Cybersecurity Certificate, Course 4: Tools of the Trade: Linux and SQL (Study Notes)
Plain-English notes on the Linux command line, file permissions, user management and SQL queries for security investigations. Includes practice questions with explanations.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.
1. Course overview
Analysts spend a lot of time reading logs, checking who can access what, and pulling records out of databases. Linux and SQL are the two everyday tools for that work. This course teaches you to move around a Linux system, control who can do what, and ask a database precise questions.
Core idea
Small commands do one job; you chain them together to answer big questions.
Builds on
Network and log concepts from Course 3.
Study tip
Practise daily in a safe sandbox such as a virtual machine, not on a system you rely on.
2. Weekly breakdown (study plan)
A suggested four-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.
Part 1: Operating systems and the Linux command line
- An operating system manages hardware and software. Linux is open source and common on servers, so analysts meet it constantly.
- The shell takes typed commands; Bash is the most common one. A kernel is the core that talks to hardware.
- The file system is a tree starting at
/(root). Important places:/home(user files),/etc(configuration),/var/log(logs),/tmp(temporary files). - Package managers install and update software, which is also how patches arrive.
Part 2: Navigating, reading and searching files
| Command | What it does |
|---|---|
pwd | Show where you are |
ls -la | List all files with details |
cd /var/log | Move to a folder |
cat, less, head, tail -f | Read a file, page through it, see start or end, follow new lines live |
grep -i "failed" auth.log | Show lines containing a word |
find /home -name "*.txt" | Locate files by name or attributes |
mkdir, touch, cp, mv, rm | Create folders and files, copy, move or rename, delete |
man ls | Open the manual for a command |
Pipes and redirects: | sends one command’s output into another; > writes output to a file (overwriting); >> appends. rm has no recycle bin, so double-check before deleting.
Part 3: Users and permissions
- Authorization in Linux is mostly file permissions. Each file has an owner, a group and “others”, and each of these can have read (r), write (w) and execute (x).
- Reading
-rwxr-x---: first character is the type (-file,ddirectory), then owner, group, others in sets of three. - Numeric values: r=4, w=2, x=1, added up per group. So
chmod 750 filemeans owner 7 (rwx), group 5 (r-x), others 0. - Symbolic form:
chmod g+w fileadds write for the group;chmod o-rwx fileremoves all rights from others. - Users:
whoami,id,useradd,usermod,passwd.sudoruns a command with administrator rights, which is powerful and should be used sparingly. - Least privilege applies: give the lowest permission that still allows the work.
Part 4: SQL for investigations
SQL asks questions of a relational database, which stores data in tables of rows and columns.
SELECT username, login_time FROM sign_ins WHERE success = 0;
SELECT * FROM sign_ins WHERE country NOT LIKE 'India%' AND success = 1;
SELECT username, COUNT(*) FROM sign_ins WHERE success = 0
GROUP BY username ORDER BY COUNT(*) DESC LIMIT 5;
SELECT s.username, d.device_name
FROM sign_ins s JOIN devices d ON s.device_id = d.id;
- SELECT picks columns, FROM picks the table, WHERE filters rows.
- AND, OR, NOT combine conditions; LIKE with
%matches patterns; BETWEEN handles ranges. - ORDER BY, GROUP BY, COUNT, LIMIT sort, summarise and trim results.
- JOIN connects two tables using a shared column, for example matching a login to a device or an employee.
- Analysts use these queries to find failed logins, odd times, unusual locations and affected machines. Knowing SQL also helps you understand SQL injection, where attackers sneak commands into input fields.
3. 15 must-know terms
| Term | Plain meaning |
|---|---|
| Linux | Open-source operating system common on servers |
| Kernel | Core of the OS that controls hardware |
| Shell / Bash | Program that runs your typed commands |
| CLI | Command-line interface: text-based control |
| Root | Top directory, and also the all-powerful user |
| Directory | Folder in the file system |
| Path | Location of a file, absolute or relative |
| Pipe | Sends output of one command to another |
| Permission | Rule for who can read, write or execute |
| chmod / chown | Change permissions / change owner |
| sudo | Run a command with elevated rights |
| Log file | Recorded history of system events |
| Database | Organised store of data in tables |
| Query | A question asked of a database |
| JOIN | Combining rows from two tables on a shared key |
4. Three worked examples
Example 1: Decode and fix a permission
Scenario: ls -l shows -rw-rw-rw- 1 asha staff report.csv and the file holds customer data.
Reasoning: everyone can read and write it, which breaks least privilege. Only the owner needs write, and perhaps the group needs read. Fix: chmod 640 report.csv gives owner read/write, group read, others nothing.
Example 2: Find the noisiest failed logins
Scenario: you need to see which accounts had the most failed logins in a log.
grep "Failed password" auth.log | awk '{print $9}' | sort | uniq -c | sort -nr | head
Logic: filter failed lines, pull out the username field, sort so duplicates sit together, count them, then sort by count. The exact field number depends on the log format, so inspect a line first. Takeaway: chaining small commands answers a bigger question.
Example 3: SQL investigation with a JOIN
Scenario: alerts show successful logins outside work hours, and you need the employee and device.
SELECT e.name, d.device_name, s.login_time
FROM sign_ins s
JOIN employees e ON s.emp_id = e.id
JOIN devices d ON s.device_id = d.id
WHERE s.success = 1
AND (s.login_time < '07:00' OR s.login_time > '20:00');
Next step: check whether the activity matches a legitimate shift, and escalate if not.
5. Common mistakes
- Running destructive commands carelessly.
rmand recursive deletes are permanent; check the path first. - Using
chmod 777to “make it work”. It gives everyone full access and is a security hole. - Using
sudofor everything. Reserve it for tasks that truly need admin rights. - Forgetting the WHERE clause. Without it, a query returns every row (and an UPDATE or DELETE affects every row).
- Mixing up
>and>>. One overwrites, one appends. - Ignoring case and exact spelling. Linux file names are case-sensitive; SQL string matching may be too, depending on the database.
6. 10 practice questions (tap to reveal)
Q1. Which command shows your current directory?
pwd (print working directory).
Q2. What is the difference between cat and less?
cat dumps the whole file at once; less lets you scroll and search a page at a time, which is better for long logs.
Q3. Which command shows only lines containing “denied” in a file named access.log?
grep "denied" access.log. Add -i to ignore case.
Q4. What does -rwxr-x--- mean?
A regular file where the owner can read, write and execute; the group can read and execute; others have no access.
Q5. Which chmod number gives the owner read/write, group read-only, others none?
640. Owner 4+2=6, group 4, others 0.
Q6. Why is chmod 777 usually a bad idea?
It lets anyone read, change and run the file, which violates least privilege and can enable tampering or malware.
Q7. What does a pipe (|) do?
It passes the output of the left command as input to the right command, so you can chain simple tools.
Q8. Write a query that returns all rows in sign_ins where success equals 0.
SELECT * FROM sign_ins WHERE success = 0;
Q9. What does GROUP BY username with COUNT(*) let you see?
How many rows each username has, for example how many failed attempts per account, so unusually high counts stand out.
Q10. When would you use a JOIN in an investigation?
When the facts you need sit in different tables, such as linking login events to employee names and device details.
7. YouTube search links
- Linux command line for beginners
- Linux file permissions and chmod
- grep, sort, uniq and pipes for logs
- SQL tutorial for beginners
- SQL joins for security analysts
8. One-screen revision summary
- Navigate:
pwd,ls -la,cd. Read:cat,less,head,tail -f. - Search:
grepfor text,findfor files. Chain:|; redirect with>or>>. - Permissions: r=4, w=2, x=1; owner/group/others;
chmod 640. - Users:
whoami,id,useradd,passwd,sudosparingly. - SQL core: SELECT, FROM, WHERE, AND/OR/NOT, LIKE.
- SQL summarise: ORDER BY, GROUP BY, COUNT, LIMIT; JOIN links tables.
- Safety: least privilege, no
777, check beforerm, always use WHERE.
9. What you should be able to do
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.
