CAS-004 Security Engineering Practice Question
A security administrator is configuring SSH for a jump host used to access critical servers. Which of the following is the most secure configuration option to restrict authentication and reduce the attack surface?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow only key-based authentication
Disabling password authentication and using only key-based authentication eliminates the risk of password brute force and credential theft. Listening on a non-standard port provides security through obscurity, which is not a strong control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable root login with a strong password
Why it's wrong here
Permitting root login with a password exposes the highest-privilege account to brute-force and credential-stuffing attacks, and a single compromise yields full host control. It tempts as an administrative convenience, yet PermitRootLogin no with key-based authentication is the hardened alternative.
- ✗
Allow only SSH protocol version 2
Why it's wrong here
Restricting SSH to protocol version 2 is already the default on modern OpenSSH, so it removes no meaningful attack surface here. It tempts because version 1 was cryptographically broken, but the question asks for restricting authentication methods, which this setting does not address.
- ✗
Change the default port to 2222
Why it's wrong here
Changing the port to 2222 is security through obscurity; it does not restrict authentication or reduce the attack surface, since scanners still find the service. It tempts because it cuts log noise from automated bots, but key-only authentication and disabling root login achieve the actual hardening.
- ✓
Allow only key-based authentication
Why this is correct
Key-based authentication removes password brute-forcing and credential-replay vectors entirely, since possession of the private key is required. This directly reduces the attack surface on the jump host, satisfying the stem's requirement to restrict authentication to the most secure method.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.