XK0-006 Security Practice Question
An administrator needs to prevent a specific user 'bob' from logging in via SSH while allowing other users. Which configuration directive should be added to /etc/ssh/sshd_config?
⚠ Common exam trap
The trap is that candidates may choose AllowUsers with a whitelist (like option A) thinking it blocks bob, but it also blocks all other users not in the list. The question's requirement to 'prevent bob while allowing other users' is best met by a blacklist approach using DenyUsers. This tests understanding of whitelist vs. blacklist logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DenyUsers bob
The DenyUsers directive in /etc/ssh/sshd_config explicitly blocks specific usernames from logging in via SSH. By specifying 'DenyUsers bob', only user bob is denied, while all other users remain allowed. This matches the requirement to prevent bob without affecting others. AllowUsers with a whitelist would also block bob but would require listing every other user, which is impractical and not the intended solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AllowUsers alice charlie
Why it's wrong here
AllowUsers alice charlie restricts SSH logins to those two named accounts, which excludes bob while permitting the others listed. It is tempting because it directly targets the named user, but it also denies every other legitimate account not enumerated, so it would be correct only when the allowed set is complete and fixed.
- ✗
PermitRootLogin no
Why it's wrong here
PermitRootLogin no only blocks the root account from authenticating over SSH, leaving bob's login unaffected. It is tempting because it is a common hardening directive, and it would be correct when the requirement is specifically to prevent direct root logins rather than to deny a named non-root user.
- ✓
DenyUsers bob
Why this is correct
DenyUsers bob blocks only the named account at authentication, leaving all other users unaffected, which satisfies the stem's requirement to prevent 'bob' specifically while permitting everyone else. Applied in sshd_config and reloaded, it is evaluated before AllowUsers, so no broader access rule is needed.
- ✗
AllowUsers bob
Why it's wrong here
AllowUsers bob permits bob to log in and, because AllowUsers acts as an allowlist, denies every other user. It is tempting because it names the target account, but it achieves the opposite of the requirement, and it would be correct only when bob is the sole account that should retain SSH access.
Go deeper
Related to this question
Learn chapter
Networking Fundamentals and Configuration
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.