A system administrator needs to harden a public-facing Linux server against automated brute-force attacks. Which configuration change in the /etc/ssh/sshd_config file provides the most significant reduction in the attack surface regarding credential stuffing?
Disabling password authentication forces the use of cryptographic keys, which are significantly harder to brute-force than even complex passwords. This change effectively eliminates the risk of automated credential stuffing because the server will reject any attempt that does not present a valid private key, regardless of the password's strength.
Why this answer
Securing the Secure Shell daemon is a foundational step in Linux hardening, especially for internet-accessible systems. While multiple settings contribute to a defense-in-depth strategy, moving away from knowledge-based authentication to key-based authentication represents the single most impactful change. This reduces the attack surface by requiring a digital token that cannot be guessed or easily intercepted via network sniffing techniques.
Exam trap
Candidates frequently choose settings like changing the SSH port or disabling root login, missing that disabling password authentication entirely provides the absolute strongest mitigation against credential stuffing.