Courseiva
Security →mediumMultiple Select

XK0-006 Security Practice Question

A Linux engineer needs to harden SSH access. Which TWO of the following settings should be configured in /etc/ssh/sshd_config to enhance security? (Select TWO.)

⚠ Common exam trap

Watch out — candidates often confuse 'hardening' with 'increasing limits' (like MaxAuthTries) or 'enabling convenience' (like PermitRootLogin yes), when the correct hardening choices actually restrict or disable weaker authentication methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PasswordAuthentication no

Option B (PasswordAuthentication no) is correct because disabling password-based authentication forces users to authenticate with SSH key pairs, eliminating brute-force and credential-stuffing attacks against account passwords. Option E (AllowUsers alice bob) is correct because it implements an explicit allowlist, so only the named accounts alice and bob may establish SSH sessions, denying all other valid system users. The remaining options weaken security: MaxAuthTries 6 (A) is too permissive since the default of 3 limits failed attempts more tightly, Protocol 1 (C) enables the obsolete and cryptographically broken SSH-1 protocol, and PermitRootLogin yes (D) allows direct root logins, which should be set to no or prohibit-password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MaxAuthTries 6

    Why it's wrong here

    MaxAuthTries 6 permits six authentication attempts per connection, giving brute-force attempts more room than a hardened value such as 3 or 4. It is tempting because it is a genuine sshd_config authentication directive, and limiting attempts at all feels like hardening, but the threshold is too permissive.

  • ✓

    PasswordAuthentication no

    Why this is correct

    Disables password logins, reducing risk of brute force.

  • ✗

    Protocol 1

    Why it's wrong here

    Protocol 1 is the obsolete SSH-1 protocol, which has known cryptographic weaknesses and is disabled in modern OpenSSH builds; hardening requires Protocol 2 only. It is tempting because it appears to specify an SSH protocol version explicitly, and older documentation listed it as a configurable setting.

  • ✗

    PermitRootLogin yes

    Why it's wrong here

    PermitRootLogin yes allows direct root logins over SSH, removing the accountability and privilege separation that sudo-based administration provides. It is tempting because it simplifies administrative access when engineers want unrestricted root sessions, but hardening requires disabling or restricting it, typically to prohibit-password.

  • ✓

    AllowUsers alice bob

    Why this is correct

    AllowUsers defines an explicit allowlist, so only alice and bob may authenticate over SSH; every other account is refused regardless of valid credentials. This meets the hardening requirement by shrinking the set of accounts exposed to remote login attempts.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.