Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A security administrator is hardening a Linux server and wants to verify that the SSH daemon is configured to disallow direct root logins. The administrator has already edited /etc/ssh/sshd_config and set PermitRootLogin no. Which command should the administrator run to ensure the SSH daemon reloads the configuration without terminating existing SSH sessions?

⚠ Common exam trap

The trap here is assuming that restarting the service is required to apply sshd_config changes, when a reload is sufficient and preserves active sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

systemctl reload sshd

Reloading the sshd service with systemctl reload sshd causes the daemon to re-read its configuration file without dropping existing connections, which is ideal when applying changes like PermitRootLogin no. Testing the syntax with sshd -t is good practice beforehand, but it does not activate the new setting. Restarting would disrupt sessions, and direct kill is less reliable than the systemd-managed reload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    sshd -t

    Why it's wrong here

    The -t option tests the configuration file for syntax errors and exits without applying changes or reloading the running daemon. It is useful for validation but does not cause sshd to re-read the file in the running process, so the new PermitRootLogin setting would not take effect until a reload or restart occurs.

  • ✗

    systemctl restart sshd

    Why it's wrong here

    Restarting the sshd service stops and starts the daemon, which terminates all existing SSH sessions. This would disconnect the administrator and other users, making it unsuitable when the goal is to reload configuration without disrupting active connections. It also takes longer than a reload and is unnecessary here.

  • ✗

    kill -HUP $(pidof sshd)

    Why it's wrong here

    While sending SIGHUP to the sshd process can trigger a reload, using kill directly bypasses systemd management and may target the wrong process if multiple instances exist. The systemctl reload command is the supported, service-aware method that ensures the correct unit is signaled and integrates with systemd's state tracking.

  • ✓

    systemctl reload sshd

    Why this is correct

    This command sends a SIGHUP to the sshd service, causing it to re-read its configuration file while keeping existing connections alive. It is the standard way to apply changes to /etc/ssh/sshd_config without dropping active sessions, which is exactly what the administrator needs to verify the PermitRootLogin setting.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.