XK0-006 Security Practice Question
A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)
⚠ Common exam trap
The trap here is assuming that increasing MaxAuthTries or enabling X11Forwarding improves security, when both actually expand the attack surface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set PermitRootLogin to no
Disabling root login and password authentication are two widely recommended SSH hardening measures. They force administrators to use named accounts and key-based authentication, reducing the effectiveness of brute-force and credential-stuffing attacks. The other listed changes either increase exposure or weaken authentication controls, so they do not support the goal of reducing the SSH attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set MaxAuthTries to 10
Why it's wrong here
Increasing MaxAuthTries from the default of 6 to 10 allows more authentication attempts per connection, which weakens protection against brute-force attacks. A lower value is more secure. This change does not restrict access or improve authentication security, so it is not an appropriate hardening action.
- ✗
Set UsePAM to no
Why it's wrong here
Disabling PAM integration removes the ability to use pluggable authentication modules for account policies, session limits, and other controls. This reduces flexibility and can weaken security rather than harden it. UsePAM should generally remain enabled, so this is not a recommended hardening step for the SSH service.
- ✗
Set X11Forwarding to yes
Why it's wrong here
Enabling X11 forwarding increases the attack surface by allowing graphical applications to be tunneled over SSH. It is generally recommended to disable X11 forwarding on servers that do not need it. This setting does not restrict access or strengthen authentication, so it contradicts the hardening goal.
- ✓
Set PermitRootLogin to no
Why this is correct
Disabling direct root logins forces administrators to authenticate as a normal user and then escalate privileges, which adds accountability and reduces the impact of brute-force attacks against the root account. This is a standard SSH hardening measure and directly limits a high-value authentication path on the web server.
- ✓
Set PasswordAuthentication to no
Why this is correct
Turning off password authentication requires key-based authentication, which is resistant to password guessing and credential stuffing. This reduces the attack surface by eliminating a common brute-force vector. Combined with disabling root login, it significantly strengthens the SSH service on the web server.
Go deeper
Related to this question
Learn chapter
Firewall and Security Basics
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.