CAS-004 Security Engineering Practice Question
A security engineer is configuring a Linux bastion host that must use only the strongest key-exchange method available in OpenSSH, avoiding any Diffie-Hellman group that relies on finite-field modular exponentiation. Which sshd_config directive setting should the engineer apply?
⚠ Common exam trap
Test-takers frequently confuse the directives that select ciphers or host-key signatures with the one that actually controls which key-exchange groups can be negotiated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
Restricting KexAlgorithms to the X25519-based curve25519-sha256 variants forces the server and client to use elliptic-curve Diffie-Hellman, eliminating all finite-field modular-exponentiation groups. The other directives govern ciphers or host-key signatures and leave the default key-exchange list, which still permits classic DH groups, intact. Only the KexAlgorithms restriction directly enforces the stated cryptographic constraint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
KexAlgorithms diffie-hellman-group14-sha256
Why it's wrong here
diffie-hellman-group14-sha256 is a finite-field Diffie-Hellman exchange over a 2048-bit MODP group. Although SHA-256 replaces SHA-1, the underlying key agreement is exactly the modular-exponentiation scheme the scenario requires the engineer to avoid, so this setting does not meet the stated constraint.
- ✓
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
Why this is correct
Curve25519-sha256 and its libssh.org alias implement X25519, an elliptic-curve Diffie-Hellman exchange that does not use finite-field modular exponentiation and provides strong forward secrecy. Restricting KexAlgorithms to these two entries removes all classic DH group1/group14-sha1 and ECDH NIST-curve options, satisfying the requirement to avoid finite-field DH based key exchange.
- ✗
HostKeyAlgorithms ssh-ed25519
Why it's wrong here
HostKeyAlgorithms selects the signature algorithm used to authenticate the server's host key, not the key-exchange method. Ed25519 host keys are unrelated to which Diffie-Hellman group is used for session establishment, so this directive would not stop finite-field DH key exchange from being negotiated.
- ✗
Ciphers chacha20-poly1305@openssh.com
Why it's wrong here
Ciphers controls symmetric encryption of the session, not how the shared secret is negotiated. Setting only a cipher leaves the default KexAlgorithms in place, which includes finite-field DH groups, so this directive fails to eliminate modular-exponentiation key exchange and does not satisfy the requirement.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.