XK0-006 Security Practice Question
A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?
⚠ Common exam trap
XK0-006 often tests whether candidates can distinguish genuine hardening controls from security-through-obscurity measures like non-standard ports, and whether they recognize deprecated options such as Protocol 1 as insecure rather than secure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PermitRootLogin no
Option C, PermitRootLogin no, is correct because it prevents direct root logins over SSH, forcing administrators to authenticate as an unprivileged user and then escalate privileges via sudo or su, which removes a high-value target and preserves an audit trail. Option D, PasswordAuthentication no, is correct because disabling password authentication forces the use of SSH key pairs (or another stronger method), eliminating brute-force and credential-guessing attacks against user passwords. Option A, Port 2222, merely changes the listening port and is security through obscurity—it does not fix any authentication weakness and can be scanned just as easily. Option B, X11Forwarding yes, is wrong because enabling X11 forwarding expands the attack surface and should typically be set to no on a hardened server. Option E, Protocol 1, is wrong because SSH protocol 1 is deprecated and cryptographically broken; modern sshd_config uses only protocol 2 (and the Protocol directive is obsolete in current OpenSSH).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port 2222
Why it's wrong here
Changing the listening port to 2222 only obscures the service from casual scans; it does not strengthen authentication, ciphers, or access control, so it is not a hardening setting. It is tempting as a form of security by obscurity, and would be chosen when reducing automated scan noise is the actual goal.
- ✗
X11Forwarding yes
Why it's wrong here
X11Forwarding yes tunnels the X11 protocol, exposing the server to X11-based attacks and bypassing some access controls; hardening sets it to no. It is tempting when administrators need to run graphical applications remotely, which is the legitimate scenario where enabling X11 forwarding is required.
- ✓
PermitRootLogin no
Why this is correct
Disables root SSH login, reducing attack surface.
- ✓
PasswordAuthentication no
Why this is correct
Setting PasswordAuthentication to no disables password-based SSH logins, forcing key-based authentication instead. This satisfies the hardening constraint by eliminating brute-force and credential-guessing attacks against user accounts, since only holders of the correct private key can authenticate.
- ✗
Protocol 1
Why it's wrong here
Protocol 1 is SSH-1, which has known cryptographic weaknesses and is disabled in modern OpenSSH builds; hardening requires Protocol 2 only. It is tempting because SSH-1 was the original protocol version, but it offers no security benefit and is rejected by current sshd_config parsing.
Go deeper
Related to this question
Learn chapter
Firewall and Security Basics
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.