Courseiva
Security →mediumMultiple Select

XK0-006 Security Practice Question

A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?

⚠ Common exam trap

XK0-006 often tests whether candidates can distinguish genuine hardening controls from security-through-obscurity measures like non-standard ports, and whether they recognize deprecated options such as Protocol 1 as insecure rather than secure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PermitRootLogin no

Option C, PermitRootLogin no, is correct because it prevents direct root logins over SSH, forcing administrators to authenticate as an unprivileged user and then escalate privileges via sudo or su, which removes a high-value target and preserves an audit trail. Option D, PasswordAuthentication no, is correct because disabling password authentication forces the use of SSH key pairs (or another stronger method), eliminating brute-force and credential-guessing attacks against user passwords. Option A, Port 2222, merely changes the listening port and is security through obscurity—it does not fix any authentication weakness and can be scanned just as easily. Option B, X11Forwarding yes, is wrong because enabling X11 forwarding expands the attack surface and should typically be set to no on a hardened server. Option E, Protocol 1, is wrong because SSH protocol 1 is deprecated and cryptographically broken; modern sshd_config uses only protocol 2 (and the Protocol directive is obsolete in current OpenSSH).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port 2222

    Why it's wrong here

    Changing the listening port to 2222 only obscures the service from casual scans; it does not strengthen authentication, ciphers, or access control, so it is not a hardening setting. It is tempting as a form of security by obscurity, and would be chosen when reducing automated scan noise is the actual goal.

  • ✗

    X11Forwarding yes

    Why it's wrong here

    X11Forwarding yes tunnels the X11 protocol, exposing the server to X11-based attacks and bypassing some access controls; hardening sets it to no. It is tempting when administrators need to run graphical applications remotely, which is the legitimate scenario where enabling X11 forwarding is required.

  • ✓

    PermitRootLogin no

    Why this is correct

    Disables root SSH login, reducing attack surface.

  • ✓

    PasswordAuthentication no

    Why this is correct

    Setting PasswordAuthentication to no disables password-based SSH logins, forcing key-based authentication instead. This satisfies the hardening constraint by eliminating brute-force and credential-guessing attacks against user accounts, since only holders of the correct private key can authenticate.

  • ✗

    Protocol 1

    Why it's wrong here

    Protocol 1 is SSH-1, which has known cryptographic weaknesses and is disabled in modern OpenSSH builds; hardening requires Protocol 2 only. It is tempting because SSH-1 was the original protocol version, but it offers no security benefit and is rejected by current sshd_config parsing.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.