Courseiva

XK0-006 Services and User Management Practice Question

A junior administrator runs `sudo useradd -m -s /bin/bash devops` on an Ubuntu 24.04 server, then immediately tries to SSH in as devops using a key that was copied to /home/devops/.ssh/authorized_keys. The login fails with 'Permission denied (publickey)'. The sshd_config has PubkeyAuthentication yes and PasswordAuthentication no. Which command is the most appropriate next step to resolve the login failure while preserving the intended account setup?

⚠ Common exam trap

The trap here is assuming any publickey denial means the key is wrong or the account is locked, when the usual cause after a sudo copy is wrong ownership or overly permissive modes on the .ssh path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run `sudo chown -R devops:devops /home/devops/.ssh && sudo chmod 700 /home/devops/.ssh && sudo chmod 600 /home/devops/.ssh/authorized_keys`.

When sudo is used to copy a public key into a user's home, the resulting authorized_keys and .ssh directory are typically owned by root and may be group- or world-writable. OpenSSH's StrictModes then refuses to use the key and reports 'Permission denied (publickey)'. Correcting ownership to the target user and setting directory mode 700 and file mode 600 satisfies StrictModes and restores key-based login without altering the account's shell or group membership.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run `sudo passwd -u devops` to unlock the account, then retry SSH.

    Why it's wrong here

    passwd -u removes a password lock, but the account was just created and PubkeyAuthentication is the only allowed method. A locked password does not block key-based SSH in OpenSSH; the 'Permission denied (publickey)' message points to key file permissions or ownership under StrictModes, not to account lock status, so this does not resolve the failure.

  • ✗

    Append `AllowUsers devops` to /etc/ssh/sshd_config and reload sshd.

    Why it's wrong here

    AllowUsers is an access-control directive that would be relevant only if the account were being filtered out by an existing allow/deny rule. In this scenario the failure is a publickey permission problem signaled by 'Permission denied (publickey)', and the account already exists with a valid shell, so adding AllowUsers does not change file ownership or mode and will not fix StrictModes rejection.

  • ✓

    Run `sudo chown -R devops:devops /home/devops/.ssh && sudo chmod 700 /home/devops/.ssh && sudo chmod 600 /home/devops/.ssh/authorized_keys`.

    Why this is correct

    OpenSSH's StrictModes (default yes) rejects authorized_keys if the .ssh directory or the file is group/world-writable, or if ownership is not the target user. Because the key was copied with sudo, the files are likely owned by root. Fixing ownership to devops:devops and tightening permissions to 700/600 directly addresses the cause and preserves the intended account.

  • ✗

    Regenerate the user's key pair with `ssh-keygen -t ed25519` and re-copy the public key.

    Why it's wrong here

    The key pair itself is not shown to be invalid, and regenerating it does not address the ownership and mode of the deployed authorized_keys file. Even a perfectly valid key will be ignored by sshd when StrictModes sees root-owned or writable key material inside /home/devops/.ssh, so this leaves the actual cause untouched while adding unnecessary key rotation work.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.