CAS-004 Security Engineering Practice Question
A security engineer is configuring a Linux bastion host that must expose SFTP to external partners while preventing interactive shell access for those same partner accounts. Partner keys are already deployed in each account's authorized_keys file. Which sshd_config directive combination BEST satisfies this requirement?
⚠ Common exam trap
The trap here is assuming that strong authentication directives such as disabling passwords or restricting allowed users also restrict what the authenticated session can execute.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set ForceCommand internal-sftp and ChrootDirectory /sftp/%u for the partner group in sshd_config.
Forcing the internal SFTP subsystem for matched sessions guarantees the connection can only perform file transfer, because the daemon never invokes the user's login shell. Combining that with a chroot directory confines each partner to a dedicated subtree and satisfies both the access and isolation goals with a single Match block. Authentication hardening alone does not change what a successfully authenticated session is allowed to do.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set Subsystem sftp /usr/lib/openssh/sftp-server and PermitTunnel no in the global sshd_config.
Why it's wrong here
Declaring the sftp subsystem tells the daemon where the SFTP server binary lives, and disabling tunneling blocks forwarded ports, but neither prevents a partner from requesting an interactive shell over the same authenticated session. The account's login shell is still invoked when the client asks for a shell channel, so the core requirement remains unmet.
- ✗
Set PasswordAuthentication no and PubkeyAuthentication yes for the partner group in sshd_config.
Why it's wrong here
Disabling password authentication and requiring public keys strengthens the authentication method, which is good practice, but authentication strength is orthogonal to session type. A partner with a valid key can still open an interactive shell channel, so these directives do not restrict the account to file transfer operations.
- ✗
Set PermitRootLogin no and AllowUsers partner1 partner2 in the global sshd_config.
Why it's wrong here
Restricting root login and enumerating permitted partner accounts limits who may connect, but it does not remove the ability to obtain an interactive shell. A partner who authenticates successfully still receives the shell declared in their passwd entry, so the requirement to block interactive access while permitting SFTP is not met by these two directives alone.
- ✓
Set ForceCommand internal-sftp and ChrootDirectory /sftp/%u for the partner group in sshd_config.
Why this is correct
ForceCommand internal-sftp makes the server run the built-in SFTP subsystem for every matched session regardless of what the client requests, so no shell is ever spawned, and ChrootDirectory confines each partner to their own directory tree with the path token expanded per account. This pairing delivers file transfer without interactive shell access.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.