Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is configuring a Linux bastion host that must use only the strongest key-exchange method available in OpenSSH, avoiding any Diffie-Hellman group that relies on finite-field modular exponentiation. Which sshd_config directive setting should the engineer apply?

⚠ Common exam trap

Test-takers frequently confuse the directives that select ciphers or host-key signatures with the one that actually controls which key-exchange groups can be negotiated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org

Restricting KexAlgorithms to the X25519-based curve25519-sha256 variants forces the server and client to use elliptic-curve Diffie-Hellman, eliminating all finite-field modular-exponentiation groups. The other directives govern ciphers or host-key signatures and leave the default key-exchange list, which still permits classic DH groups, intact. Only the KexAlgorithms restriction directly enforces the stated cryptographic constraint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KexAlgorithms diffie-hellman-group14-sha256

    Why it's wrong here

    diffie-hellman-group14-sha256 is a finite-field Diffie-Hellman exchange over a 2048-bit MODP group. Although SHA-256 replaces SHA-1, the underlying key agreement is exactly the modular-exponentiation scheme the scenario requires the engineer to avoid, so this setting does not meet the stated constraint.

  • ✓

    KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org

    Why this is correct

    Curve25519-sha256 and its libssh.org alias implement X25519, an elliptic-curve Diffie-Hellman exchange that does not use finite-field modular exponentiation and provides strong forward secrecy. Restricting KexAlgorithms to these two entries removes all classic DH group1/group14-sha1 and ECDH NIST-curve options, satisfying the requirement to avoid finite-field DH based key exchange.

  • ✗

    HostKeyAlgorithms ssh-ed25519

    Why it's wrong here

    HostKeyAlgorithms selects the signature algorithm used to authenticate the server's host key, not the key-exchange method. Ed25519 host keys are unrelated to which Diffie-Hellman group is used for session establishment, so this directive would not stop finite-field DH key exchange from being negotiated.

  • ✗

    Ciphers chacha20-poly1305@openssh.com

    Why it's wrong here

    Ciphers controls symmetric encryption of the session, not how the shared secret is negotiated. Setting only a cipher leaves the default KexAlgorithms in place, which includes finite-field DH groups, so this directive fails to eliminate modular-exponentiation key exchange and does not satisfy the requirement.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.