Courseiva
Security →mediumMultiple Select

XK0-006 Security Practice Question

A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)

⚠ Common exam trap

The trap here is assuming that increasing MaxAuthTries or enabling X11Forwarding improves security, when both actually expand the attack surface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set PermitRootLogin to no

Disabling root login and password authentication are two widely recommended SSH hardening measures. They force administrators to use named accounts and key-based authentication, reducing the effectiveness of brute-force and credential-stuffing attacks. The other listed changes either increase exposure or weaken authentication controls, so they do not support the goal of reducing the SSH attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set MaxAuthTries to 10

    Why it's wrong here

    Increasing MaxAuthTries from the default of 6 to 10 allows more authentication attempts per connection, which weakens protection against brute-force attacks. A lower value is more secure. This change does not restrict access or improve authentication security, so it is not an appropriate hardening action.

  • ✗

    Set UsePAM to no

    Why it's wrong here

    Disabling PAM integration removes the ability to use pluggable authentication modules for account policies, session limits, and other controls. This reduces flexibility and can weaken security rather than harden it. UsePAM should generally remain enabled, so this is not a recommended hardening step for the SSH service.

  • ✗

    Set X11Forwarding to yes

    Why it's wrong here

    Enabling X11 forwarding increases the attack surface by allowing graphical applications to be tunneled over SSH. It is generally recommended to disable X11 forwarding on servers that do not need it. This setting does not restrict access or strengthen authentication, so it contradicts the hardening goal.

  • ✓

    Set PermitRootLogin to no

    Why this is correct

    Disabling direct root logins forces administrators to authenticate as a normal user and then escalate privileges, which adds accountability and reduces the impact of brute-force attacks against the root account. This is a standard SSH hardening measure and directly limits a high-value authentication path on the web server.

  • ✓

    Set PasswordAuthentication to no

    Why this is correct

    Turning off password authentication requires key-based authentication, which is resistant to password guessing and credential stuffing. This reduces the attack surface by eliminating a common brute-force vector. Combined with disabling root login, it significantly strengthens the SSH service on the web server.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.