Courseiva
mediumMultiple Choice

XK0-006 Practice Question: A user is trying to log in to a Linux server via…

A user is trying to log in to a Linux server via SSH but receives 'Permission denied (publickey,gssapi-keyex,gssapi-with-mic)'. The user's public key is in ~/.ssh/authorized_keys with proper permissions (600) and owned by the user. The server's sshd_config has 'PubkeyAuthentication yes' and 'PasswordAuthentication no'. What is the most likely additional cause?

⚠ Common exam trap

CompTIA often tests the subtlety that SSH's `StrictModes` checks parent directory permissions, not just the key file, leading candidates to overlook home directory permissions when the key file itself appears correct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user's home directory has incorrect permissions (e.g., group-writable).

SSH server's `StrictModes` (enabled by default) checks that the user's home directory is not group-writable or world-writable. If the home directory has group-write permission (e.g., 775), SSH refuses to trust `~/.ssh/authorized_keys` even if the file itself has 600 permissions. This is a security measure to prevent other group members from modifying the authorized_keys file indirectly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server's firewall is blocking port 22.

    Why it's wrong here

    A firewall blocking port 22 would prevent the TCP connection entirely, producing a timeout or "connection refused", not an authentication-stage "Permission denied" listing offered methods. Firewall rules are the right focus when SSH is unreachable from the outset, such as silent hangs or immediate refusals before any banner exchange.

  • ✓

    The user's home directory has incorrect permissions (e.g., group-writable).

    Why this is correct

    OpenSSH's StrictModes rejects authentication when the home directory is group- or world-writable, even if authorized_keys itself is 600. The server silently falls back to other methods, producing the publickey denial despite correct key file permissions and PubkeyAuthentication being enabled.

  • ✗

    SELinux is blocking the key authentication.

    Why it's wrong here

    SELinux denials on SSH keys typically surface as AVC messages and failures reading authorized_keys, and would not produce this clean authentication-method banner. It is tempting because SELinux does restrict sshd file access, but the enumerated publickey methods indicate sshd rejected the key itself, not that policy blocked the read.

  • ✗

    The SSH server is not running.

    Why it's wrong here

    If sshd were not running, the client would report connection refused or timeout, never a Permission denied listing authentication methods. It is tempting because a stopped service blocks logins, but the banner proves sshd completed the handshake and rejected the offered key, so the cause lies in key or account configuration.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.