Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

An administrator configures /etc/ssh/sshd_config with the following settings: PermitRootLogin no, PasswordAuthentication no, AllowUsers alice bob, MaxAuthTries 2. After restarting sshd, which of the following is true?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User bob can log in using a public key.

PasswordAuthentication no disables password logins, so public key authentication is required. PermitRootLogin no prevents root login entirely. AllowUsers restricts to alice and bob only. MaxAuthTries 2 limits authentication attempts. So root cannot log in even with keys, and alice/bob must use keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User charlie can log in using a public key.

    Why it's wrong here

    AllowUsers restricts logins to alice and bob, so charlie is rejected regardless of authentication method. Public-key authentication being enabled is tempting, but the AllowUsers allowlist is the binding constraint that excludes charlie before any key is considered.

  • ✓

    User bob can log in using a public key.

    Why this is correct

    PasswordAuthentication no forces public-key authentication, and AllowUsers alice bob permits bob, so bob can log in with a public key. PermitRootLogin no blocks root, and MaxAuthTries 2 limits attempts, but neither prevents bob's key-based login.

  • ✗

    User alice can log in using a password.

    Why it's wrong here

    PasswordAuthentication no disables password-based authentication for every account, so alice cannot authenticate with a password despite being listed in AllowUsers. AllowUsers only restricts who may connect, not how. Alice could log in using an SSH key instead, which is the intended configuration.

  • ✗

    Root can log in using a valid password.

    Why it's wrong here

    PermitRootLogin no blocks all root logins regardless of authentication method, and PasswordAuthentication no removes password auth entirely. Root could only connect if a key were authorised and root login were permitted. The directive exists precisely to prevent direct privileged access over SSH.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.