Courseiva
Networking →mediumMultiple Choice

LFCS Networking Practice Question

A financial firm requires all internal SSH connections to be encrypted with at least 256-bit ciphers. An administrator is configuring the SSH server. Which configuration line should be added to /etc/ssh/sshd_config?

⚠ Common exam trap

Many exam-takers confuse MACs, KexAlgorithms, or HostKeyAlgorithms with encryption ciphers, assuming any directive with '256' or 'sha256' implies 256-bit encryption, when only the Ciphers directive controls the symmetric encryption algorithm strength.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ciphers aes256-ctr

The Ciphers directive in sshd_config explicitly controls the symmetric encryption algorithms used to encrypt SSH session data. The cipher aes256-ctr provides 256-bit encryption, meeting the firm's requirement for at least 256-bit ciphers. Other directives like MACs, KexAlgorithms, or HostKeyAlgorithms do not directly set the encryption cipher strength.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MACs hmac-sha2-256

    Why it's wrong here

    MACs select the message authentication algorithm protecting integrity, not the cipher encrypting the session, so hmac-sha2-256 leaves the encryption strength unchanged. It is tempting because the 256 in its name matches the requirement, and it would be correct when the policy mandates a minimum-strength integrity algorithm rather than cipher.

  • ✗

    KexAlgorithms diffie-hellman-group-exchange-sha256

    Why it's wrong here

    KexAlgorithms governs key exchange, determining how the shared secret is derived, not the symmetric cipher that encrypts the session data. It is tempting because diffie-hellman-group-exchange-sha256 sounds strong and 256-bit, and it would be correct when the policy requires a minimum Diffie-Hellman group size or specific key exchange method.

  • ✓

    Ciphers aes256-ctr

    Why this is correct

    Restricting the server to `aes256-ctr` satisfies the 256-bit minimum by offering only that cipher during negotiation. Unlike `aes128-ctr`, it meets the stated strength floor, and unlike broad lists such as `aes256-ctr,aes128-ctr`, it cannot silently downgrade to a weaker algorithm.

  • ✗

    HostKeyAlgorithms ssh-rsa

    Why it's wrong here

    HostKeyAlgorithms restricts which host key signature algorithms the server offers for authentication, not the symmetric cipher encrypting the connection. It is tempting because ssh-rsa appears cryptographic and key-related, and it would be correct when the requirement is to constrain host key types, for example to remove ssh-dss.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.