Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

An administrator needs to ensure that only users from the 'ops' group can SSH into a server. Which configuration in /etc/ssh/sshd_config accomplishes this?

⚠ Common exam trap

Candidates often confuse `AllowUsers` (which matches usernames) with `AllowGroups` (which matches group membership), leading candidates to select option C when the requirement specifies group-based restriction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AllowGroups ops

The `AllowGroups` directive in `/etc/ssh/sshd_config` restricts SSH access to only users who are members of the specified group. By setting `AllowGroups ops`, only users belonging to the 'ops' group will be permitted to log in via SSH, which directly meets the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AllowGroups ops

    Why this is correct

    AllowGroups ops restricts SSH logins to members of the ops group, satisfying the requirement that only that group connects. When AllowGroups is set, all users outside the listed groups are denied, regardless of other account settings.

  • ✗

    Match Group ops DenyUsers *

    Why it's wrong here

    DenyUsers inside a Match Group block denies only matching users, and the wildcard pattern does not match the intended group membership semantics, so non-ops accounts still authenticate. It is tempting because Match blocks scope directives per group, and would be correct for denying a named subset rather than restricting access to one group.

  • ✗

    AllowUsers ops

    Why it's wrong here

    AllowUsers matches login names, not group membership, so listing 'ops' permits only a user literally named ops and locks out every other group member. It is tempting because AllowUsers restricts who may authenticate, and would be correct if the requirement named individual accounts instead of a group.

  • ✗

    DenyUsers all

    Why it's wrong here

    DenyUsers all blocks every account, including the 'ops' group, so no one could authenticate. DenyUsers is designed to blacklist specific named accounts or patterns while leaving others permitted; it would suit excluding particular users, not restricting access to one group. Group-based SSH restrictions require AllowGroups, which matches the 'ops' membership directly.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.