Courseiva
easyMultiple Choice

XK0-006 Practice Question: After a security audit, it is recommended to…

After a security audit, it is recommended to disable SSH password authentication in favor of key-based authentication. Which configuration line should be set in /etc/ssh/sshd_config?

⚠ Common exam trap

Candidates often confuse `PasswordAuthentication` with `PubkeyAuthentication` or think that disabling password authentication requires setting it to `yes`, when in fact the directive must be set to `no` to disable it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PasswordAuthentication no

Disabling password authentication forces SSH to use key-based authentication, which is more secure against brute-force attacks. Setting `PasswordAuthentication no` in `/etc/ssh/sshd_config` prevents SSH from prompting for a password, requiring a valid SSH key pair for authentication. This aligns with the security audit's recommendation to disable password authentication in favor of key-based authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PasswordAuthentication yes

    Why it's wrong here

    PasswordAuthentication yes explicitly keeps password logins enabled, directly contradicting the audit's requirement to disable them. It is tempting because it is the default line many administrators recognise, yet the correct setting is PasswordAuthentication no, leaving key-based authentication as the only method.

  • ✗

    PubkeyAuthentication no

    Why it's wrong here

    Setting PubkeyAuthentication to no disables public-key logins entirely, which is the opposite of the audit recommendation. It is tempting because the directive name matches the topic, yet the correct line is PasswordAuthentication no, which disables password logins while leaving key authentication enabled.

  • ✓

    PasswordAuthentication no

    Why this is correct

    Setting `PasswordAuthentication no` in sshd_config forces the daemon to reject all password-based logins, leaving public-key authentication as the only accepted method. This directly satisfies the audit requirement to disable SSH password authentication in favour of key-based authentication, and takes effect after restarting or reloading the SSH service.

  • ✗

    ChallengeResponseAuthentication yes

    Why it's wrong here

    ChallengeResponseAuthentication yes governs keyboard-interactive authentication, not password authentication, so it leaves PasswordAuthentication enabled and the audit finding unresolved. It is tempting because it controls PAM-backed prompts, and it would be the right line when a scenario requires keyboard-interactive or one-time-passcode logins instead of disabling passwords.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.