Courseiva
GNU and Unix Commands →mediumMultiple Choice

LPIC-1 GNU and Unix Commands Practice Question

Exhibit

$ cat /etc/ssh/sshd_config | grep -i "PermitRootLogin"
PermitRootLogin prohibit-password
$ cat /etc/ssh/sshd_config | grep -i "PasswordAuthentication"
PasswordAuthentication no

Refer to the exhibit. Which statement is true about SSH root login on this server?

⚠ Common exam trap

The trap here is that candidates often misinterpret `prohibit-password` as a complete ban on root login, when in fact it only blocks password-based authentication and still allows key-based login.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Root can log in using a public key.

The exhibit shows that `PermitRootLogin` is set to `prohibit-password` in the SSH server configuration. This setting explicitly disables password-based authentication for root, but allows root login using public key authentication. Therefore, root can log in only by presenting a valid private key that matches an authorized public key, making option C correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Root can log in only from localhost.

    Why it's wrong here

    A PermitRootLogin value of prohibit-password or without-password blocks password authentication but still allows key-based root logins from any host, so restricting root to localhost is not implied. It would be correct if the directive were PermitRootLogin forced-commands-only or an AllowUsers root@localhost entry existed.

  • ✗

    Root cannot log in at all.

    Why it's wrong here

    The exhibit shows PermitRootLogin set to a value that still permits root authentication, such as yes or prohibit-password, so root is not fully blocked. It is tempting because prohibit-password sounds like a denial, but that keyword only disables password authentication while key-based root logins remain possible.

  • ✓

    Root can log in using a public key.

    Why this is correct

    The sshd_config directive PermitRootLogin is set to prohibit-password, which blocks password authentication for root while still allowing public-key authentication. Root therefore cannot log in with a password but can authenticate using an authorised key pair.

  • ✗

    Root can log in with a password.

    Why it's wrong here

    If the exhibit shows PermitRootLogin prohibit-password or without-password, password authentication for root is explicitly disabled, so this statement is false. It is tempting because PermitRootLogin yes does allow password logins, but that is not the value shown in the configuration.

About these practice questions

One of 402 original LPIC-1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.