XK0-006 Security Practice Question
To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?
⚠ Common exam trap
XK0-006 often tests the confusion between similar-sounding directives — candidates must know the exact keyword 'PermitRootLogin' rather than plausible but invalid names like 'RootLogin' or user-list directives like DenyUsers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PermitRootLogin no
The correct directive in /etc/ssh/sshd_config to prevent the root account from logging in over SSH is 'PermitRootLogin no'. This is the exact keyword recognized by OpenSSH's sshd, and setting it to 'no' blocks all root logins regardless of authentication method. After editing the file, the administrator must reload or restart sshd (e.g., systemctl reload sshd) for the change to take effect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RootLogin no
Why it's wrong here
RootLogin is not a valid sshd_config directive; the correct keyword is PermitRootLogin, so sshd rejects or ignores this line and root login remains enabled. It is tempting because the name matches the intent, and PermitRootLogin no would be the right setting for this hardening task.
- ✓
PermitRootLogin no
Why this is correct
PermitRootLogin no directly blocks root authentication over SSH, satisfying the requirement to disable root login. The directive accepts values such as yes, no, prohibit-password and forced-commands-only; setting no rejects all root logins regardless of authentication method, which is stricter than prohibit-password. The sshd service must be reloaded for the change to take effect.
- ✗
DenyUsers root
Why it's wrong here
DenyUsers blocks named accounts after authentication attempts, not the root login directive itself. It is tempting because it can exclude root, but PermitRootLogin no is the directive that disables root SSH logins; DenyUsers is for denying specific non-root users.
- ✗
AllowUsers root
Why it's wrong here
AllowUsers root restricts which accounts may authenticate but does not disable root's own login; it would actually permit root if listed. It is tempting because AllowUsers genuinely controls SSH access lists, and would be correct when whitelisting specific non-root administrators rather than blocking root.
Go deeper
Related to this question
Learn chapter
File Transfer and Remote Access
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
Key term
systemctl
systemctl is the command-line tool used to inspect, start, stop, enable, or disable services managed by the systemd init system in Linux.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.