easyMultiple Choice
XK0-006 Practice Question: A system administrator needs to restrict SSH…
A system administrator needs to restrict SSH access to a Linux server to only users in the 'sshusers' group. Which configuration change achieves this?
⚠ Common exam trap
CompTIA often tests the distinction between 'AllowUsers' (which expects usernames) and 'AllowGroups' (which expects group names), leading candidates to incorrectly choose 'AllowUsers sshusers' thinking it applies to the group rather than a user literal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'AllowGroups sshusers' to /etc/ssh/sshd_config
The 'AllowGroups' directive in /etc/ssh/sshd_config restricts SSH access to only users who are members of the specified group. When set to 'AllowGroups sshusers', only users belonging to the 'sshusers' group will be permitted to log in via SSH, effectively blocking all others. This is the standard method for group-based access control in OpenSSH.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add 'DenyUsers *' to /etc/ssh/sshd_config
Why it's wrong here
DenyUsers * blocks every account, including the 'sshusers' members, so nobody can log in. It is tempting because DenyUsers does restrict access by user or group, and would suit blacklisting specific accounts, but the stem needs an allowlist permitting only one group.
- ✗
Set 'PermitRootLogin no' in /etc/ssh/sshd_config
Why it's wrong here
PermitRootLogin no only bars the root account from SSH; ordinary users outside 'sshusers' still authenticate, so group restriction is unmet. It is tempting because it hardens SSH against direct root logins, and would be correct where the requirement is disabling root access specifically.
- ✓
Add 'AllowGroups sshusers' to /etc/ssh/sshd_config
Why this is correct
Adding `AllowGroups sshusers` to `/etc/ssh/sshd_config` makes the SSH daemon evaluate group membership at authentication time, permitting only accounts belonging to the `sshusers` group. This directly satisfies the stem's constraint of restricting access to that single group, and it scales cleanly as membership changes without editing per-user entries.
- ✗
Add 'AllowUsers sshusers' to /etc/ssh/sshd_config
Why it's wrong here
AllowUsers matches login names, not group names, so 'sshusers' would be treated as a username and every group member would be denied. It is tempting because AllowUsers does restrict SSH logins, and it is the correct directive when the requirement names individual accounts rather than a group.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.