A security engineer is hardening an SSH server. The policy requires disabling all legacy algorithms and using only modern, secure cryptography. Which THREE of the following configurations should the engineer apply?
Restricting HMAC to SHA-2 or stronger removes MD5 and SHA-1 message authentication codes, which are collision-prone and deprecated. This directly satisfies the policy's requirement to disable legacy algorithms, since SSH MAC negotiation would otherwise still permit these weak integrity checks.
Why this answer
Option A is correct because configuring the MAC (HMAC) list to SHA-2 or stronger (e.g., hmac-sha2-256, hmac-sha2-512) removes weak legacy integrity algorithms such as hmac-md5 and hmac-sha1, which are vulnerable to collision and downgrade attacks. Option D is correct because disabling password authentication and permitting only public-key authentication eliminates brute-force and credential-replay risks, since SSH keys provide stronger, non-reusable cryptographic proof of identity. Option E is correct because restricting KEX algorithms to curve25519-sha256 uses modern elliptic-curve Diffie-Hellman with strong forward secrecy, excluding outdated groups like diffie-hellman-group1-sha1.
Option B is wrong because SSH protocol version 1 is deprecated and insecure (vulnerable to MITM and CRC-32 attacks); only SSH-2 should be allowed. Option C is wrong because enabling direct root login with a password violates least-privilege and hardening best practices, exposing the most privileged account to brute-force attacks.
Exam trap
CAS-005 often tests the temptation to allow legacy protocols or root password login 'for compatibility' — candidates must recognise that these options directly violate the hardening requirement and are never correct in a secure configuration context.