LFCS Networking Practice Question
A financial firm requires all internal SSH connections to be encrypted with at least 256-bit ciphers. An administrator is configuring the SSH server. Which configuration line should be added to /etc/ssh/sshd_config?
⚠ Common exam trap
Many exam-takers confuse MACs, KexAlgorithms, or HostKeyAlgorithms with encryption ciphers, assuming any directive with '256' or 'sha256' implies 256-bit encryption, when only the Ciphers directive controls the symmetric encryption algorithm strength.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ciphers aes256-ctr
The Ciphers directive in sshd_config explicitly controls the symmetric encryption algorithms used to encrypt SSH session data. The cipher aes256-ctr provides 256-bit encryption, meeting the firm's requirement for at least 256-bit ciphers. Other directives like MACs, KexAlgorithms, or HostKeyAlgorithms do not directly set the encryption cipher strength.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACs hmac-sha2-256
Why it's wrong here
MACs select the message authentication algorithm protecting integrity, not the cipher encrypting the session, so hmac-sha2-256 leaves the encryption strength unchanged. It is tempting because the 256 in its name matches the requirement, and it would be correct when the policy mandates a minimum-strength integrity algorithm rather than cipher.
- ✗
KexAlgorithms diffie-hellman-group-exchange-sha256
Why it's wrong here
KexAlgorithms governs key exchange, determining how the shared secret is derived, not the symmetric cipher that encrypts the session data. It is tempting because diffie-hellman-group-exchange-sha256 sounds strong and 256-bit, and it would be correct when the policy requires a minimum Diffie-Hellman group size or specific key exchange method.
- ✓
Ciphers aes256-ctr
Why this is correct
Restricting the server to `aes256-ctr` satisfies the 256-bit minimum by offering only that cipher during negotiation. Unlike `aes128-ctr`, it meets the stated strength floor, and unlike broad lists such as `aes256-ctr,aes128-ctr`, it cannot silently downgrade to a weaker algorithm.
- ✗
HostKeyAlgorithms ssh-rsa
Why it's wrong here
HostKeyAlgorithms restricts which host key signature algorithms the server offers for authentication, not the symmetric cipher encrypting the connection. It is tempting because ssh-rsa appears cryptographic and key-related, and it would be correct when the requirement is to constrain host key types, for example to remove ssh-dss.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.