Google Cybersecurity Certificate, Course 4: Tools of the Trade: Linux and SQL (Study Notes)

    Plain-English notes on the Linux command line, file permissions, user management and SQL queries for security investigations. Includes practice questions with explanations.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.

    1. Course overview

    Analysts spend a lot of time reading logs, checking who can access what, and pulling records out of databases. Linux and SQL are the two everyday tools for that work. This course teaches you to move around a Linux system, control who can do what, and ask a database precise questions.

    Core idea

    Small commands do one job; you chain them together to answer big questions.

    Builds on

    Network and log concepts from Course 3.

    Study tip

    Practise daily in a safe sandbox such as a virtual machine, not on a system you rely on.

    2. Weekly breakdown (study plan)

    A suggested four-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.

    Part 1: Operating systems and the Linux command line
    • An operating system manages hardware and software. Linux is open source and common on servers, so analysts meet it constantly.
    • The shell takes typed commands; Bash is the most common one. A kernel is the core that talks to hardware.
    • The file system is a tree starting at / (root). Important places: /home (user files), /etc (configuration), /var/log (logs), /tmp (temporary files).
    • Package managers install and update software, which is also how patches arrive.
    Part 2: Navigating, reading and searching files
    CommandWhat it does
    pwdShow where you are
    ls -laList all files with details
    cd /var/logMove to a folder
    cat, less, head, tail -fRead a file, page through it, see start or end, follow new lines live
    grep -i "failed" auth.logShow lines containing a word
    find /home -name "*.txt"Locate files by name or attributes
    mkdir, touch, cp, mv, rmCreate folders and files, copy, move or rename, delete
    man lsOpen the manual for a command

    Pipes and redirects: | sends one command’s output into another; > writes output to a file (overwriting); >> appends. rm has no recycle bin, so double-check before deleting.

    Part 3: Users and permissions
    • Authorization in Linux is mostly file permissions. Each file has an owner, a group and “others”, and each of these can have read (r), write (w) and execute (x).
    • Reading -rwxr-x---: first character is the type (- file, d directory), then owner, group, others in sets of three.
    • Numeric values: r=4, w=2, x=1, added up per group. So chmod 750 file means owner 7 (rwx), group 5 (r-x), others 0.
    • Symbolic form: chmod g+w file adds write for the group; chmod o-rwx file removes all rights from others.
    • Users: whoami, id, useradd, usermod, passwd. sudo runs a command with administrator rights, which is powerful and should be used sparingly.
    • Least privilege applies: give the lowest permission that still allows the work.
    Part 4: SQL for investigations

    SQL asks questions of a relational database, which stores data in tables of rows and columns.

    SELECT username, login_time FROM sign_ins WHERE success = 0;
    SELECT * FROM sign_ins WHERE country NOT LIKE 'India%' AND success = 1;
    SELECT username, COUNT(*) FROM sign_ins WHERE success = 0
      GROUP BY username ORDER BY COUNT(*) DESC LIMIT 5;
    SELECT s.username, d.device_name
      FROM sign_ins s JOIN devices d ON s.device_id = d.id;
    • SELECT picks columns, FROM picks the table, WHERE filters rows.
    • AND, OR, NOT combine conditions; LIKE with % matches patterns; BETWEEN handles ranges.
    • ORDER BY, GROUP BY, COUNT, LIMIT sort, summarise and trim results.
    • JOIN connects two tables using a shared column, for example matching a login to a device or an employee.
    • Analysts use these queries to find failed logins, odd times, unusual locations and affected machines. Knowing SQL also helps you understand SQL injection, where attackers sneak commands into input fields.

    3. 15 must-know terms

    TermPlain meaning
    LinuxOpen-source operating system common on servers
    KernelCore of the OS that controls hardware
    Shell / BashProgram that runs your typed commands
    CLICommand-line interface: text-based control
    RootTop directory, and also the all-powerful user
    DirectoryFolder in the file system
    PathLocation of a file, absolute or relative
    PipeSends output of one command to another
    PermissionRule for who can read, write or execute
    chmod / chownChange permissions / change owner
    sudoRun a command with elevated rights
    Log fileRecorded history of system events
    DatabaseOrganised store of data in tables
    QueryA question asked of a database
    JOINCombining rows from two tables on a shared key

    4. Three worked examples

    Example 1: Decode and fix a permission

    Scenario: ls -l shows -rw-rw-rw- 1 asha staff report.csv and the file holds customer data.

    Reasoning: everyone can read and write it, which breaks least privilege. Only the owner needs write, and perhaps the group needs read. Fix: chmod 640 report.csv gives owner read/write, group read, others nothing.

    Example 2: Find the noisiest failed logins

    Scenario: you need to see which accounts had the most failed logins in a log.

    grep "Failed password" auth.log | awk '{print $9}' | sort | uniq -c | sort -nr | head

    Logic: filter failed lines, pull out the username field, sort so duplicates sit together, count them, then sort by count. The exact field number depends on the log format, so inspect a line first. Takeaway: chaining small commands answers a bigger question.

    Example 3: SQL investigation with a JOIN

    Scenario: alerts show successful logins outside work hours, and you need the employee and device.

    SELECT e.name, d.device_name, s.login_time
    FROM sign_ins s
    JOIN employees e ON s.emp_id = e.id
    JOIN devices d ON s.device_id = d.id
    WHERE s.success = 1
      AND (s.login_time < '07:00' OR s.login_time > '20:00');

    Next step: check whether the activity matches a legitimate shift, and escalate if not.

    5. Common mistakes

    • Running destructive commands carelessly. rm and recursive deletes are permanent; check the path first.
    • Using chmod 777 to “make it work”. It gives everyone full access and is a security hole.
    • Using sudo for everything. Reserve it for tasks that truly need admin rights.
    • Forgetting the WHERE clause. Without it, a query returns every row (and an UPDATE or DELETE affects every row).
    • Mixing up > and >>. One overwrites, one appends.
    • Ignoring case and exact spelling. Linux file names are case-sensitive; SQL string matching may be too, depending on the database.

    6. 10 practice questions (tap to reveal)

    Q1. Which command shows your current directory?

    pwd (print working directory).

    Q2. What is the difference between cat and less?

    cat dumps the whole file at once; less lets you scroll and search a page at a time, which is better for long logs.

    Q3. Which command shows only lines containing “denied” in a file named access.log?

    grep "denied" access.log. Add -i to ignore case.

    Q4. What does -rwxr-x--- mean?

    A regular file where the owner can read, write and execute; the group can read and execute; others have no access.

    Q5. Which chmod number gives the owner read/write, group read-only, others none?

    640. Owner 4+2=6, group 4, others 0.

    Q6. Why is chmod 777 usually a bad idea?

    It lets anyone read, change and run the file, which violates least privilege and can enable tampering or malware.

    Q7. What does a pipe (|) do?

    It passes the output of the left command as input to the right command, so you can chain simple tools.

    Q8. Write a query that returns all rows in sign_ins where success equals 0.

    SELECT * FROM sign_ins WHERE success = 0;

    Q9. What does GROUP BY username with COUNT(*) let you see?

    How many rows each username has, for example how many failed attempts per account, so unusually high counts stand out.

    Q10. When would you use a JOIN in an investigation?

    When the facts you need sit in different tables, such as linking login events to employee names and device details.

    7. YouTube search links

    8. One-screen revision summary

    • Navigate: pwd, ls -la, cd. Read: cat, less, head, tail -f.
    • Search: grep for text, find for files. Chain: |; redirect with > or >>.
    • Permissions: r=4, w=2, x=1; owner/group/others; chmod 640.
    • Users: whoami, id, useradd, passwd, sudo sparingly.
    • SQL core: SELECT, FROM, WHERE, AND/OR/NOT, LIKE.
    • SQL summarise: ORDER BY, GROUP BY, COUNT, LIMIT; JOIN links tables.
    • Safety: least privilege, no 777, check before rm, always use WHERE.

    9. What you should be able to do

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.