CAS-004 Security Engineering Practice Question
A security engineer is configuring a Linux server to enforce encrypted remote administration. The requirement is that after the initial key exchange, session keys must be rotated periodically to limit the impact of a compromised session key. Which OpenSSH configuration directive should the engineer use to achieve this?
⚠ Common exam trap
Test-takers frequently confuse cipher selection with key rotation, assuming that choosing a strong cipher automatically provides forward secrecy or periodic rekeying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set RekeyLimit to 1G 1h in the sshd_config file.
The RekeyLimit directive in OpenSSH allows administrators to enforce periodic rekeying based on data volume, time, or both. By setting it to 1G 1h, the session key is refreshed after 1 gigabyte of data or one hour, whichever occurs first. This limits the amount of data encrypted under a single key, reducing the impact of a key compromise. Other directives control cipher selection, key exchange algorithms, or integrity algorithms but do not manage key rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set Ciphers to aes256-ctr in the sshd_config file.
Why it's wrong here
The Ciphers directive restricts the list of allowed symmetric encryption algorithms but does not control how often session keys are rotated. Even with a strong cipher like aes256-ctr, the same key could be used for the entire session, which fails the requirement to periodically rotate keys.
- ✗
Set MACs to hmac-sha2-512 in the sshd_config file.
Why it's wrong here
The MACs directive selects message authentication code algorithms for integrity checking. It has no bearing on session key lifetime or rekeying. Configuring a strong MAC does not rotate keys, so this option does not satisfy the stated requirement.
- ✓
Set RekeyLimit to 1G 1h in the sshd_config file.
Why this is correct
RekeyLimit specifies the maximum amount of data and/or time before the session key is renegotiated. Setting it to 1G 1h forces a new key exchange after 1 gigabyte of data or one hour, whichever comes first, thereby rotating session keys and limiting exposure if a key is compromised. This directly satisfies the requirement.
- ✗
Set KexAlgorithms to diffie-hellman-group-exchange-sha256 in the sshd_config file.
Why it's wrong here
KexAlgorithms defines which key exchange methods are permitted during the initial handshake. While it affects how the initial session key is established, it does not cause periodic rekeying during an active session. Therefore, it does not meet the requirement for session key rotation.
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.