XK0-006 Security Practice Question
A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure pam_faillock.so to lock accounts after failed attempts
Option B is correct because configuring pam_faillock.so in the PAM stack enforces account lockout after a defined number of failed authentication attempts (e.g., deny=5, unlock_time=900), directly mitigating brute-force and password-guessing attacks against the weak password policy. Option C is correct because pam_pwquality.so enforces password complexity requirements such as minimum length (minlen), character classes (ucredit, lcredit, dcredit, ocredit), and dictionary checks, which addresses the audit finding of weak password policies at their source. Option D is correct because setting PasswordAuthentication no in sshd_config disables password-based SSH authentication entirely, forcing key-based authentication and eliminating the password-guessing attack surface the audit flagged; this requires reloading sshd (systemctl reload sshd) to take effect. Option A does not belong because merely changing the SSH port to 2222 is security through obscurity and does not fix the underlying weak authentication or password policy issues. Option E does not belong because setting PermitRootLogin yes permits direct root logins over SSH, which increases risk rather than improving security; it should be set to no or prohibit-password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change SSH port to 2222
Why it's wrong here
Moving SSH to port 2222 only obscures the service from casual scans; sshd still accepts passwords, so weak credentials remain guessable. It is tempting because port obfuscation reduces automated noise, and would be correct alongside key-only authentication as defence in depth, not as the fix.
- ✓
Configure pam_faillock.so to lock accounts after failed attempts
Why this is correct
Configuring pam_faillock.so enforces account lockout after repeated failed authentication attempts, directly mitigating brute-force attacks against the weak password policy identified in the audit. It operates at the PAM authentication layer, so the protection applies across all services using PAM, not SSH alone, hardening the system beyond the password-strength weakness.
- ✓
Configure pam_pwquality.so to enforce password complexity
Why this is correct
Configuring pam_pwquality.so enforces complexity rules such as minimum length, character classes and dictionary checks at password change time, directly remedying the weak password policies the audit identified. This hardens credentials against brute-force and guessing attacks, satisfying the stem's requirement to strengthen authentication rather than merely restricting SSH access.
- ✓
Set PasswordAuthentication no in sshd_config
Why this is correct
Setting `PasswordAuthentication no` in `sshd_config` disables password-based SSH authentication entirely, forcing key-based logins and directly eliminating the weak-password exposure the audit flagged. This satisfies the stem's requirement to remove password logins, since attackers can no longer brute-force or guess credentials over SSH.
- ✗
Set PermitRootLogin yes
Why it's wrong here
PermitRootLogin yes lets attackers authenticate directly as root, removing the need to escalate after compromising a user account, and does nothing about password strength. It is tempting because root access is sometimes needed for administration, and would be correct only when restricted to prohibit-password or forced-commands.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.