Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security administrator is configuring SSH for a jump host used to access critical servers. Which of the following is the most secure configuration option to restrict authentication and reduce the attack surface?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow only key-based authentication

Disabling password authentication and using only key-based authentication eliminates the risk of password brute force and credential theft. Listening on a non-standard port provides security through obscurity, which is not a strong control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable root login with a strong password

    Why it's wrong here

    Permitting root login with a password exposes the highest-privilege account to brute-force and credential-stuffing attacks, and a single compromise yields full host control. It tempts as an administrative convenience, yet PermitRootLogin no with key-based authentication is the hardened alternative.

  • ✗

    Allow only SSH protocol version 2

    Why it's wrong here

    Restricting SSH to protocol version 2 is already the default on modern OpenSSH, so it removes no meaningful attack surface here. It tempts because version 1 was cryptographically broken, but the question asks for restricting authentication methods, which this setting does not address.

  • ✗

    Change the default port to 2222

    Why it's wrong here

    Changing the port to 2222 is security through obscurity; it does not restrict authentication or reduce the attack surface, since scanners still find the service. It tempts because it cuts log noise from automated bots, but key-only authentication and disabling root login achieve the actual hardening.

  • ✓

    Allow only key-based authentication

    Why this is correct

    Key-based authentication removes password brute-forcing and credential-replay vectors entirely, since possession of the private key is required. This directly reduces the attack surface on the jump host, satisfying the stem's requirement to restrict authentication to the most secure method.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.