Courseiva
mediumMultiple Choice

How to Restrict SSH Access to a Specific Group Using AllowGroups

A Linux server is configured to allow SSH access for remote administration. The security team wants to limit SSH access to only users in the 'ssh-users' group. Which configuration should be added to /etc/ssh/sshd_config?

Quick Answer

The answer is to add `AllowGroups ssh-users` to `/etc/ssh/sshd_config`. This directive works by instructing the SSH daemon to check the group membership of any user attempting to log in; only users who are members of the specified group—in this case, `ssh-users`—will be granted access, while all others are denied even if they have valid credentials. On the CompTIA Linux+ XK0-005 exam, this question tests your understanding of SSH access control directives, often contrasting `AllowGroups` with `AllowUsers` or `DenyGroups`. A common trap is confusing `AllowGroups` with `AllowUsers`—remember that `AllowGroups` checks group membership, not individual usernames. A helpful memory tip: think of "AllowGroups" as a bouncer checking for a group pass, not a guest list.

⚠ Common exam trap

A common mix-up: candidates confuse AllowUsers (which takes usernames) with AllowGroups (which takes group names), leading them to incorrectly select option A thinking it will filter by group membership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AllowGroups ssh-users

The AllowGroups directive in /etc/ssh/sshd_config restricts SSH logins to only those users who are members of the specified group. By setting 'AllowGroups ssh-users', only users belonging to the 'ssh-users' group will be permitted to authenticate via SSH, directly fulfilling the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AllowUsers ssh-users

    Why it's wrong here

    AllowUsers expects usernames, not group names, so ssh-users would be interpreted as a literal account and no group members would match. It is tempting because AllowUsers does restrict SSH logins, and it would be correct if the requirement named individual user accounts rather than a group.

  • ✓

    AllowGroups ssh-users

    Why this is correct

    `AllowGroups ssh-users` restricts SSH logins to members of the named group, satisfying the requirement to limit access to the 'ssh-users' group. The sshd daemon checks this directive during authentication and rejects any user not belonging to a listed group, regardless of valid credentials. It is the precise directive for group-based SSH access control.

  • ✗

    DenyUsers root

    Why it's wrong here

    DenyUsers root blocks only the root account and leaves every other user, including non-members of ssh-users, able to authenticate. It is tempting because DenyUsers is a valid sshd_config access directive, and it would be correct if the requirement were to prevent root logins rather than restrict access to a group.

  • ✗

    PermitRootLogin yes

    Why it's wrong here

    PermitRootLogin yes explicitly allows the root account to log in over SSH, which neither restricts access to the ssh-users group nor aligns with the security team's stated goal. It is tempting as a hardening directive, and would be relevant when disabling direct root logins, but it does not address group-based access control.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on XK0-006

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to restrict SSH access to only users in the 'sshusers' group. Which configuration should be added to /etc/ssh/sshd_config?

medium
  • A.AllowUsers sshusers
  • B.DenyUsers sshusers
  • ✓ C.AllowGroups sshusers
  • D.PermitRootLogin no

Why C: The `AllowGroups` directive in `/etc/ssh/sshd_config` restricts SSH login to users who are members of the specified group. By setting `AllowGroups sshusers`, only users belonging to the 'sshusers' group will be permitted to authenticate via SSH, while all others are denied. This matches the administrator's requirement precisely.

Variation 2. A system administrator needs to restrict SSH access to a Linux server to only users in the 'sshusers' group. Which configuration change achieves this?

easy
  • A.Add 'DenyUsers *' to /etc/ssh/sshd_config
  • B.Set 'PermitRootLogin no' in /etc/ssh/sshd_config
  • ✓ C.Add 'AllowGroups sshusers' to /etc/ssh/sshd_config
  • D.Add 'AllowUsers sshusers' to /etc/ssh/sshd_config

Why C: The 'AllowGroups' directive in /etc/ssh/sshd_config restricts SSH access to only users who are members of the specified group. When set to 'AllowGroups sshusers', only users belonging to the 'sshusers' group will be permitted to log in via SSH, effectively blocking all others. This is the standard method for group-based access control in OpenSSH.

Variation 3. A systems administrator needs to restrict SSH access to a Linux server so that only users in the 'sshusers' group can log in. Which configuration change should be made in /etc/ssh/sshd_config?

medium
  • A.Add 'AllowUsers sshusers'
  • B.Add 'DenyGroups all'
  • ✓ C.Add 'AllowGroups sshusers'
  • D.Add 'PermitRootLogin no' and add users to sshusers

Why C: The 'AllowGroups' directive in /etc/ssh/sshd_config restricts SSH login to only users who are members of the specified group. By adding 'AllowGroups sshusers', only users in the 'sshusers' group will be permitted to authenticate via SSH, while all others are denied. This is the standard OpenSSH mechanism for group-based access control.

Variation 4. A system administrator wants to restrict SSH access to a specific group of users. Which two methods can achieve this? (Select TWO.)

easy
  • A.Use /etc/security/access.conf
  • ✓ B.Edit /etc/ssh/sshd_config and set AllowGroups engineers
  • C.Modify /etc/pam.d/sshd to use pam_listfile.so
  • D.Add users to the sshd group
  • ✓ E.Edit /etc/ssh/sshd_config and set AllowUsers user1,user2,user3

Why B: Option B is correct because the AllowGroups directive in /etc/ssh/sshd_config restricts SSH logins to members of the named groups (e.g., engineers), which is exactly the group-based restriction the administrator wants. Option E is correct because AllowUsers in /etc/ssh/sshd_config limits SSH access to the explicitly listed user accounts, achieving the same goal of restricting who may log in over SSH. Option A is not the right tool here: /etc/security/access.conf is enforced by pam_access.so and is not SSH-specific, so it does not directly configure sshd's own access control. Option C is unnecessary and indirect; while pam_listfile.so can restrict services via PAM, it is not one of the two standard sshd_config methods for limiting SSH by group or user. Option D is incorrect because adding users to an sshd group has no effect on SSH login permissions; sshd does not use group membership in that way.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.