Al-Siraj University · Technical College of Engineering · Cybersecurity Engineering Techniques

Week 2 — Exploring Linux Distributions

CSTE2103 — Linux Fundamentals · Level 2 · Semester 3
Class time
2 h lecture + 2 h lab
Study at home
about 3 h
Outcomes
LO 1, 2, 6 (start of 11)
Before this
Week 1 + your VM
What is in this page
1. What you will learn
2. Two minutes to remember Week 1
3. Two videos to watch
4. What is inside a distribution
5. Two ways to release a system
6. LTS and the version numbers
7. Repositories and the package manager
8. The desktop is not the distribution
9. The families, one by one
10. How to choose a distribution
11. Download safely: the checksum
12. Practice terminal (try it here)
13. Command card
14. Mistakes everybody makes
15. Small dictionary + abbreviations
16. Laboratory 2 — planning
17. Check yourself
18. Learning outcomes
19. Next week and extra videos

1. What You Will Learn Today

After this session you will be able to:

  1. List the six things that make one distribution different from another.
  2. Explain LTS and say why a server and a student make different choices.
  3. Describe where software comes from in Linux, and use apt to search and install a package.
  4. Choose a suitable distribution for a given job and defend your choice.
  5. Check that a downloaded system image is complete and was not modified.

2. Two Minutes to Remember Week 1

Kernel The engine. One project, written since 1991, the same in every distribution.
Distribution The complete car built around that engine. This week is about the car.
Shell / terminal The program that reads your command, inside the window that shows the letters.
root and sudo root is the administrator. You work as a normal user and put sudo before a command that changes the system. You will need this today.

3. Watch Before You Read Further

A fast tour of the distributions, then a calm explanation of how to choose one.

Video 1 — Every Linux distribution explained in 17 minutes
▶ Open on YouTube if the video does not appear — explainerguy01. Do not try to remember all the names; only the families.
Video 2 — Choosing a Linux distribution
▶ Open on YouTube if the video does not appear — Gardiner Bryant

4. What Is Inside a Distribution

There are hundreds of distributions and they all use the same kernel. So what is actually different? Six things — and when you compare two distributions, you compare these six:

A DISTRIBUTION Ubuntu, Fedora, Kali … 1. Kernel version new and fast, or old and tested 2. Package manager apt, dnf, zypper, pacman 3. Release model fixed dates, or rolling 4. Support period 9 months … 10 years 5. Default programs office tools, or security tools 6. Desktop or server with a screen, or text only The kernel inside all of them is the same project — only the version differs.
The useful consequence. What you learn in this course is not "Ubuntu". The commands, the file tree and the permissions are the same everywhere. When you change distribution, you mostly change one word: the name of the package manager.

5. Two Ways to Release a System

This single decision explains most of the difference between distributions.

FIXED RELEASE — Ubuntu, Debian, RHEL, Fedora 24.04 26.04you are here 28.04 Between the big versions: only security fixes (the small dots). Nothing changes suddenly. ROLLING RELEASE — Arch, Manjaro, openSUSE Tumbleweed No versions at all: small updates arrive every few days, for ever. Newest software, more surprises.
  Fixed release Rolling release
New version On a known date (Ubuntu: every 6 months, LTS every 2 years) Never — the system is always "the current one"
Software age Older, but tested for months The newest that exists
Risk Low — a server can run for years untouched Higher — an update can change or break something
Good for Servers, companies, laboratories, students Personal machines of experienced users

6. LTS and the Version Numbers

Ubuntu numbers are not random. 26.04 means the version published in the fourth month of 2026. Every two years the April version is marked LTS — Long Term Support: it receives security updates for five years instead of nine months.

26.04 LTS 26 = the year 2026 04 = the month April LTS = 5 years of support (only the April version of an even year) Security updates you receive: 26.04 LTS — five years of security updates Apr 2026 → 2031 26.10 a normal release — nine months only, then you must upgrade Rule for this course and for real servers: always choose the LTS.
The version of our laboratory. Ubuntu Server 26.04.1 LTS, codename Resolute Raccoon, published on 23 April 2026 with Linux kernel 7.0, supported until 2031. The .1 matters: it is the corrected image published in August, four months after the first release. A laboratory or a company never installs the April image of an LTS — it waits for the .1.

Other families do the same thing with other numbers:

Distribution New version arrives Security updates last
Ubuntu LTSevery 2 years (April)5 years
Ubuntu normalevery 6 months9 months
Debian stableabout every 2 yearsabout 5 years
Fedoraevery 6 monthsabout 13 months
RHEL / Rocky / Almaevery 3 years10 years
Archno versions (rolling)always the newest
Why a security engineer cares. "Support" means somebody is still publishing fixes for newly discovered holes. A machine running a system whose support ended does not become slower — it becomes undefended. Every known hole stays open for ever. This is one of the most common findings in real security audits.

7. Repositories and the Package Manager

In Windows you search the web, download a .exe from some site and hope it is clean. Linux does not work like that. Every distribution has its own repositories: official servers holding thousands of checked programs. The package manager — on Ubuntu it is called apt, the Advanced Package Tool — takes what you ask for from there.

REPOSITORY archive.ubuntu.com htop_3.4.0.deb nmap_7.95.deb · 60 000 more signed apt (package manager) 1. checks the signature 2. finds what else is needed 3. installs everything in order YOUR MACHINE the program is installed and appears in the list of installed packages Dependencies — the real work of a package manager A program needs other pieces to run. You ask for one package; apt finds the five it depends on, and installs them too. Security note Every package is signed by the distribution. A file downloaded from a random website is not — and that is how many machines get infected.

The commands are simple, and they are the same idea in every family:

You want to… Ubuntu / Debian Fedora / RHEL
refresh the list of softwaresudo apt update
substitute user do · Advanced Package Tool
sudo dnf check-update
search for a programapt search htopdnf search htop
read the details firstapt show htopdnf info htop
install itsudo apt install htopsudo dnf install htop
remove itsudo apt remove htopsudo dnf remove htop
update the whole systemsudo apt upgrade
Advanced Package Tool
sudo dnf upgrade
see what is installedapt list --installed
Advanced Package Tool
dnf list installed

Two habits to build now: run apt update before you install anything, and read apt show before you accept a package you do not know.

See it done — installing software in Arabic
▶ Open on YouTube — Yousef Alshamani (تثبيت البرامج على أوبونتو)
The same subject in English, in more detail
▶ Open on YouTube — Akamai Developers, with Jay LaCroix

8. The Desktop Is Not the Distribution

Beginners think "Ubuntu looks like this and Fedora looks like that". Wrong. What you see — the panel, the menu, the windows — is a separate program called a desktop environment, and you can put almost any of them on almost any distribution.

GNOME simple, default on Ubuntu KDE Plasma many settings, looks like Windows XFCE light, for old computers student@srv:~$ _ no windows no mouse no wasted memory SERVER — no desktop what we use in the laboratory

Our laboratory machine is Ubuntu Server: no desktop at all. That is not poverty — it is the normal choice for a server. A desktop would eat memory, add programs nobody uses, and every extra program is one more door an attacker can try.

9. The Families, One by One

Name Family Who uses it, and why
Ubuntu Debian The most common starting point. Huge amount of help on the internet, an LTS every two years, and most cloud servers run it. Our choice for the laboratory.
Debian Debian The father of Ubuntu. Run by volunteers, extremely stable, slower to add new software. Very common on servers that must simply keep working.
Linux Mint Debian Ubuntu with a friendlier desktop. A good first system for someone coming from Windows.
Kali Linux Debian Debian with six hundred security-testing tools already installed. You will meet it later in your programme. It is a working tool for authorised tests, not a daily system for a student — and installing it does not by itself make anybody a security engineer.
Fedora Red Hat Where Red Hat tests new ideas. Newest software, short support. Popular with developers.
RHEL Red Hat The paid enterprise system: ten years of support and a company to call. Banks, telecoms and ministries buy it. Rocky Linux and AlmaLinux are free rebuilds of it.
openSUSE SUSE Strong in European industry. Known for YaST, a single tool to configure the whole system.
Arch Arch You build the system yourself, piece by piece. Excellent documentation. Teaches a lot — after you already know the basics.

10. How to Choose a Distribution

There is no "best distribution". There is only the right one for a given job. Ask three questions in this order:

What is the machine for? A server website, database, files Learning / study this course, your VM Security testing authorised work only Old computer 1–2 GB of memory Ubuntu Server LTS or Debian / Rocky Ubuntu LTS most answers online Kali in a virtual machine Mint XFCE or Debian XFCE Question 2 — how many years must this machine keep working without a reinstall? More than two years → a system with long support (Ubuntu LTS, Debian, Rocky). Never a rolling release. Question 3 — who will keep it running? Choose what your team already knows. A perfect distribution nobody can administer is the wrong distribution.
A warning about Kali. Students often install Kali in the first month because it looks professional. Its tools are made to test networks, and using them on a network you do not own is a crime in Iraq as everywhere else. In this programme you will use such tools inside a closed laboratory, with permission, and only after you understand the systems you are testing.

11. Download Safely — the Checksum

You are about to download a 2.6 GB file and then give it control of a whole computer. Two things can go wrong: the download breaks in the middle, or somebody gives you a modified image with something extra inside. Both are solved by the same tool.

A checksum (or fingerprint, or hash) — here SHA-256, the Secure Hash Algorithm with a 256-bit answer — is a long number calculated from every single byte of a file. Change one byte — one — and the number changes completely. The project publishes the correct number; you calculate yours and compare.

Your downloaded file ubuntu-26.04.1-...iso 2.6 GB sha256sum Your fingerprint c7f4a9d21b6e0538af17… 64 characters The official number c7f4a9d21b6e0538af17… from ubuntu.com compare the two lines EQUAL → use it The file is complete and nobody changed a single byte of it. DIFFERENT → delete it Broken download, or somebody gave you a modified image. Never install it.

How you do it on each system:

# on Linux
$ sha256sum ubuntu-26.04.1-live-server-amd64.iso
 
# on Windows (PowerShell)
> Get-FileHash .\ubuntu-26.04.1-live-server-amd64.iso -Algorithm SHA256
 
# on macOS
$ shasum -a 256 ubuntu-26.04.1-live-server-amd64.iso

There is one more level, which you will study later: the file of checksums is itself signed with a GPG key (GNU Privacy Guard) belonging to the project. The checksum proves the file did not change; the signature proves the checksum itself came from Ubuntu and not from an attacker who replaced both.

Watch: checking a checksum on Windows
▶ Open on YouTube — John Mintalar. You need this for the laboratory.

12. Practice Terminal

Install a package and verify a download here first — then do it for real on your virtual machine.

Practice Terminal — The Software Store of Ubuntu

A safe copy of an Ubuntu machine. This week it also understands the package commands apt and the checksum command sha256sum. Nothing here touches a real computer. Type help to begin.
Your 7 missions
0 / 7 finished
student@cste-lab: practice terminal — week 2
student@cste-lab:~$
Tab = complete the word  ·  Up / Down arrows = commands you typed before  ·  help = the list of commands  ·  commands that change the system need sudo

13. Command Card — Week 2

Add this card to the one from Week 1.

Command What it does
lsb_release -a
Linux Standard Base, all
Shows the distribution, its version and its codename
cat /etc/os-release
concatenate
The same information, works on every distribution
sudo apt updateRefreshes the list of available software (does not install anything)
sudo apt upgradeInstalls the newer versions of what you already have
apt search <word>
Advanced Package Tool
Searches the repositories for a program
apt show <package>
Advanced Package Tool
Shows the details: version, size, what it is for
sudo apt install <p>
Advanced Package Tool
Installs a package and everything it depends on
sudo apt remove <p>
Advanced Package Tool
Removes a package
apt list --installedLists everything installed on the machine
apt list --upgradable
Advanced Package Tool
Lists what has a newer version waiting
sha256sum <file>
Secure Hash Algorithm, 256 bits
Calculates the fingerprint of a file
dnf / zypper / pacman
Dandified YUM · SUSE tool · package manager
The same work on Fedora / SUSE / Arch

14. Mistakes Everybody Makes This Week

Six problems you will certainly meet, and the answer to each.

What you see Why What to do
Permission denied · Are you root? Installing changes the whole system, so it needs administrator rights. Put sudo in front: sudo apt install …
E: Unable to locate package Your list of available software is old, or the name is misspelled. Run sudo apt update, then apt search the name.
"I ran apt update but nothing was installed" update refreshes the list. upgrade installs. Remember the pair: update, then upgrade.
A .rpm file will not install on Ubuntu That is the package format of the Red Hat family. Look for the same program with apt search. It is almost always there.
Downloading a program from the first site Google shows Those files are signed by nobody. This is how machines get infected. Use the repositories first. They are the safe source.
Installing an image without checking its checksum A broken or modified image can fail halfway — or work perfectly and spy on you. Always compare the fingerprint. It takes thirty seconds.

15. Small Dictionary of This Week

Word Meaning in one line
PackageOne program wrapped in a file together with its description and its list of needs (.deb or .rpm).
RepositoryThe official server holding thousands of checked packages for your distribution.
MirrorA copy of that server in another country, so the download is faster.
DependencyAnother package that a program needs in order to run. apt installs them for you.
LTSLong Term Support — a version that keeps receiving security fixes for five years.
Rolling releaseA system with no versions: small updates arrive continuously.
CodenameThe nickname of a version — Ubuntu 26.04 is "resolute". Commands and files often use it.
ISO imageOne big file containing a whole installation disk.
Checksum / hashA fingerprint calculated from a file, used to prove the file did not change.
GPG signatureA cryptographic proof of who published a file. Packages and checksum files are signed.
Desktop environmentThe graphical face of the system (GNOME, KDE, XFCE). A server has none.
SnapshotA saved state of a virtual machine, so you can return to it after a mistake.

Where these short names come from

The package tools and the security words are all abbreviations. Here is what each one actually says.

Command The name means What that tells you
aptAdvanced Package ToolThe software store of the Debian family: apt update, apt search, apt install.
dpkgDebian packageThe low-level tool under apt. A package file ends in .deb — Debian.
dnfDandified YUMThe Red Hat family tool. YUM itself = Yellowdog Updater, Modified.
rpmRPM Package ManagerThe package format of the Red Hat family — a .rpm file. The name originally meant Red Hat Package Manager.
pacmanpackage managerThe Arch Linux tool.
zyppernot an abbreviationThe openSUSE tool — simply its name.
lsb_releaseLinux Standard Base releasePrints the distribution, its version and its codename.
sha256sumSHA-256 sumCalculates the SHA-256 fingerprint of a file. SHA = Secure Hash Algorithm; 256 = the length of the number in bits.
htopthe friendlier toptop shows the processes using most of the machine; htop shows the same with colours and a tree.

Other short names you will meet

Short name It stands for In one line
LTSLong Term SupportA version that keeps receiving security fixes for five years instead of nine months.
ISOan ISO 9660 disc imageA whole installation disc kept in one file. The standard is published by the International Organization for Standardization.
SHA-256Secure Hash Algorithm, 256 bitsThe fingerprint you compare after a download.
GPGGNU Privacy GuardThe tool that signs files. The signature proves who published the checksum.
RHELRed Hat Enterprise LinuxThe paid enterprise system with ten years of support.
amd64 / x86_64the 64-bit PC processor familyYou will see it in every package name and image name.
GNOMEfrom “GNU Network Object Model Environment”A desktop environment. The project dropped the old expansion; today it is simply a name.
KDEK Desktop EnvironmentA desktop environment with many settings.
XFCEbegan as “XForms Common Environment”A light desktop environment for older machines.

Notice the pattern: apt, dnf, zypper and pacman are four names for the same job — take a checked, signed program from the official servers and install it with everything it needs.

16. Laboratory 2 — Planning a Linux Machine

2 hours · each student alone · deliver one PDF · 10 marks

Last week you installed a machine because the teacher told you to. This week you decide why. Planning before installing is what separates an engineer from a person who clicks Next.

Step 1 — Choose for three real situations (about 30 minutes)

For each situation below, write in your report: the distribution you choose, the release model, how long it is supported, and two lines of justification.

# The situation
AThe college needs a web server for the student portal. It must run for at least four years with as few reinstalls as possible, and one technician will look after it.
BA laboratory of fifteen old computers with 2 GB of memory each, to be used for teaching programming to first-year students.
CA virtual machine for a graduation project in network security testing, isolated from the college network.
Step 2 — Verify the image you downloaded (about 30 minutes)
  1. Open the official Ubuntu page and find the published SHA-256 number of the image used in the laboratory.
  2. Calculate the fingerprint of your own copy (Get-FileHash on Windows, sha256sum on Linux).
  3. Put both numbers in your report, one under the other, and say clearly whether they match.
  4. Answer in two lines: what exactly would you conclude if they did not match, and what would you do?
Step 3 — Learn your own machine (about 30 minutes)

On the virtual machine from Week 1, run these and keep a screenshot of each:

$ lsb_release -a
$ cat /etc/apt/sources.list # where your software comes from
$ sudo apt update
$ apt list --upgradable
$ sudo apt upgrade
$ apt show htop
$ sudo apt install htop
$ htop # press q to leave it

Write one line about what htop shows you that free -h does not.

Step 4 — Protect your work with a snapshot (about 15 minutes)

In VirtualBox, with the machine switched off, open Snapshots and take one called clean-after-week2. From now on, whenever you break something in a later laboratory, you return to this point in one click instead of reinstalling for an hour. Put a screenshot of the snapshot list in your report.

Marks (10)
Three situations answered with a real justification (not one word)3
Both checksums shown, compared, and the "what if" question answered3
The eight commands with screenshots, htop installed and running3
Snapshot created and shown1
Send one PDF named CSTE2103_Lab2_<your number>.pdf on IQ-LEARN before the next laboratory.

17. Check Yourself

Answer first, then click to open the answer. Quiz 1 is in Week 5 and covers Weeks 1 to 5.
Part A — Choose one answer
1. Ubuntu 26.04 was published in: (a) April 2026   (b) the 26th week of 2004   (c) version 26, revision 4
(a) April 2026. Year, then month. The April version of an even year is the LTS.
2. sudo apt update does what? (a) installs new versions   (b) refreshes the list of available software   (c) upgrades the kernel
(b) refreshes the list. To actually install the newer versions you then run sudo apt upgrade.
3. A rolling release is best for: (a) a bank's server   (b) an experienced user's own machine   (c) a first-year laboratory
(b). Newest software, but updates can change things at any moment — not what a server or a classroom needs.
4. Two computers show the same desktop but different package managers. They are: (a) the same distribution   (b) different distributions   (c) impossible
(b) different distributions. The desktop is a separate program — GNOME runs on Ubuntu and on Fedora. The package manager belongs to the distribution.
5. Your checksum does not match the published one. You should: (a) install it anyway   (b) download again from the official site   (c) rename the file
(b). Either the download broke or the file was modified. In both cases the file is not usable.
6. Support of your server's system ended two years ago. The main danger is: (a) it becomes slow   (b) no more security fixes   (c) the licence expires
(b). Newly discovered holes are never closed. The machine keeps working normally — and stays open.
Part B — Answer in one or two lines
7. Name four of the six things that make one distribution different from another.
Kernel version, package manager and repositories, release model, support period, default programs, desktop or server.
8. Why is installing from a repository safer than downloading a program from a website?
Packages in a repository are built and cryptographically signed by the distribution, and the package manager refuses anything whose signature does not match. A file from a random website carries no such proof.
9. What is a dependency, and who deals with it?
Another package that a program needs in order to run. The package manager finds them all and installs them in the right order.
10. You must choose a system for a hospital server that will run for eight years. What do you choose and why?
A long-support system: RHEL (or Rocky/AlmaLinux) with ten years of support, or Ubuntu LTS. Never a rolling release, and never a normal nine-month release — the support must outlive the machine.
11. What does a checksum prove, and what does it not prove?
It proves the file is exactly the one whose number was published — not one byte changed. It does not by itself prove who published that number; the GPG signature on the checksum file is what proves that.
12. Translate to the Red Hat family: sudo apt install nmap
sudo dnf install nmap — same idea, different package manager.

18. Link to the Module Learning Outcomes

Outcome From the module description form Covered by
LO 1 Basic Linux knowledge — identify the differences between the different distributions Sections 4–6, 8–10; questions 1, 3, 4, 7
LO 2 Installing and configuring Linux systems to meet personal or professional needs Section 10; laboratory steps 1, 3, 4
LO 6 Software and package management — install, update and remove software Section 7, 13; terminal missions 2–5; laboratory step 3
LO 11 Applying security principles Sections 6, 7, 11; terminal missions 6–7; laboratory step 2

Examined in Quiz 1 (Week 5), the midterm (Week 8) and the final examination.

19. Next Week and Extra Practice

Week 3 — Navigating the file system. The tree you saw in Week 1, but this time you will live in it: moving, looking, finding, and understanding absolute and relative paths. Bring your virtual machine with the snapshot already taken.

Books
  • Required: Nemeth, Snyder, Hein & Whaley, UNIX and Linux System Administration Handbook, 5th edition — the chapter on software installation and management.
  • Easier to read: Shotts, The Linux Command Line — the chapter "Package Management".
If you want more video (optional)
A full Arabic course, useful all semester: دورة تعلم لينكس كاملة باللغة العربية — Ahmed Eid
A longer English beginner course: Linux For Beginners — Full Course — Amigoscode
CSTE2103 — Linux Fundamentals · Week 2 of 15 · Department of Cybersecurity Engineering Techniques