Courseiva
Security →hardMultiple Select

XK0-006 Security Practice Question

A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure pam_faillock.so to lock accounts after failed attempts

Option B is correct because configuring pam_faillock.so in the PAM stack enforces account lockout after a defined number of failed authentication attempts (e.g., deny=5, unlock_time=900), directly mitigating brute-force and password-guessing attacks against the weak password policy. Option C is correct because pam_pwquality.so enforces password complexity requirements such as minimum length (minlen), character classes (ucredit, lcredit, dcredit, ocredit), and dictionary checks, which addresses the audit finding of weak password policies at their source. Option D is correct because setting PasswordAuthentication no in sshd_config disables password-based SSH authentication entirely, forcing key-based authentication and eliminating the password-guessing attack surface the audit flagged; this requires reloading sshd (systemctl reload sshd) to take effect. Option A does not belong because merely changing the SSH port to 2222 is security through obscurity and does not fix the underlying weak authentication or password policy issues. Option E does not belong because setting PermitRootLogin yes permits direct root logins over SSH, which increases risk rather than improving security; it should be set to no or prohibit-password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change SSH port to 2222

    Why it's wrong here

    Moving SSH to port 2222 only obscures the service from casual scans; sshd still accepts passwords, so weak credentials remain guessable. It is tempting because port obfuscation reduces automated noise, and would be correct alongside key-only authentication as defence in depth, not as the fix.

  • ✓

    Configure pam_faillock.so to lock accounts after failed attempts

    Why this is correct

    Configuring pam_faillock.so enforces account lockout after repeated failed authentication attempts, directly mitigating brute-force attacks against the weak password policy identified in the audit. It operates at the PAM authentication layer, so the protection applies across all services using PAM, not SSH alone, hardening the system beyond the password-strength weakness.

  • ✓

    Configure pam_pwquality.so to enforce password complexity

    Why this is correct

    Configuring pam_pwquality.so enforces complexity rules such as minimum length, character classes and dictionary checks at password change time, directly remedying the weak password policies the audit identified. This hardens credentials against brute-force and guessing attacks, satisfying the stem's requirement to strengthen authentication rather than merely restricting SSH access.

  • ✓

    Set PasswordAuthentication no in sshd_config

    Why this is correct

    Setting `PasswordAuthentication no` in `sshd_config` disables password-based SSH authentication entirely, forcing key-based logins and directly eliminating the weak-password exposure the audit flagged. This satisfies the stem's requirement to remove password logins, since attackers can no longer brute-force or guess credentials over SSH.

  • ✗

    Set PermitRootLogin yes

    Why it's wrong here

    PermitRootLogin yes lets attackers authenticate directly as root, removing the need to escalate after compromising a user account, and does nothing about password strength. It is tempting because root access is sometimes needed for administration, and would be correct only when restricted to prohibit-password or forced-commands.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.