Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?

⚠ Common exam trap

XK0-006 often tests the confusion between similar-sounding directives — candidates must know the exact keyword 'PermitRootLogin' rather than plausible but invalid names like 'RootLogin' or user-list directives like DenyUsers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PermitRootLogin no

The correct directive in /etc/ssh/sshd_config to prevent the root account from logging in over SSH is 'PermitRootLogin no'. This is the exact keyword recognized by OpenSSH's sshd, and setting it to 'no' blocks all root logins regardless of authentication method. After editing the file, the administrator must reload or restart sshd (e.g., systemctl reload sshd) for the change to take effect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RootLogin no

    Why it's wrong here

    RootLogin is not a valid sshd_config directive; the correct keyword is PermitRootLogin, so sshd rejects or ignores this line and root login remains enabled. It is tempting because the name matches the intent, and PermitRootLogin no would be the right setting for this hardening task.

  • ✓

    PermitRootLogin no

    Why this is correct

    PermitRootLogin no directly blocks root authentication over SSH, satisfying the requirement to disable root login. The directive accepts values such as yes, no, prohibit-password and forced-commands-only; setting no rejects all root logins regardless of authentication method, which is stricter than prohibit-password. The sshd service must be reloaded for the change to take effect.

  • ✗

    DenyUsers root

    Why it's wrong here

    DenyUsers blocks named accounts after authentication attempts, not the root login directive itself. It is tempting because it can exclude root, but PermitRootLogin no is the directive that disables root SSH logins; DenyUsers is for denying specific non-root users.

  • ✗

    AllowUsers root

    Why it's wrong here

    AllowUsers root restricts which accounts may authenticate but does not disable root's own login; it would actually permit root if listed. It is tempting because AllowUsers genuinely controls SSH access lists, and would be correct when whitelisting specific non-root administrators rather than blocking root.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.