easyMultiple Choice
XK0-006 Practice Question: After a security audit, it is recommended to…
After a security audit, it is recommended to disable SSH password authentication in favor of key-based authentication. Which configuration line should be set in /etc/ssh/sshd_config?
⚠ Common exam trap
Candidates often confuse `PasswordAuthentication` with `PubkeyAuthentication` or think that disabling password authentication requires setting it to `yes`, when in fact the directive must be set to `no` to disable it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PasswordAuthentication no
Disabling password authentication forces SSH to use key-based authentication, which is more secure against brute-force attacks. Setting `PasswordAuthentication no` in `/etc/ssh/sshd_config` prevents SSH from prompting for a password, requiring a valid SSH key pair for authentication. This aligns with the security audit's recommendation to disable password authentication in favor of key-based authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PasswordAuthentication yes
Why it's wrong here
PasswordAuthentication yes explicitly keeps password logins enabled, directly contradicting the audit's requirement to disable them. It is tempting because it is the default line many administrators recognise, yet the correct setting is PasswordAuthentication no, leaving key-based authentication as the only method.
- ✗
PubkeyAuthentication no
Why it's wrong here
Setting PubkeyAuthentication to no disables public-key logins entirely, which is the opposite of the audit recommendation. It is tempting because the directive name matches the topic, yet the correct line is PasswordAuthentication no, which disables password logins while leaving key authentication enabled.
- ✓
PasswordAuthentication no
Why this is correct
Setting `PasswordAuthentication no` in sshd_config forces the daemon to reject all password-based logins, leaving public-key authentication as the only accepted method. This directly satisfies the audit requirement to disable SSH password authentication in favour of key-based authentication, and takes effect after restarting or reloading the SSH service.
- ✗
ChallengeResponseAuthentication yes
Why it's wrong here
ChallengeResponseAuthentication yes governs keyboard-interactive authentication, not password authentication, so it leaves PasswordAuthentication enabled and the audit finding unresolved. It is tempting because it controls PAM-backed prompts, and it would be the right line when a scenario requires keyboard-interactive or one-time-passcode logins instead of disabling passwords.
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.