LPIC-2 System Security Practice Question
Which TWO of the following are effective methods to secure SSH access on a Linux server? (Choose two.)
⚠ Common exam trap
Many exam-takers think disabling root login (Option A) is one of the two correct answers, but the question specifically asks for two methods from the list, and the correct pair is C and E; disabling root login is a valid security measure but is not listed as correct in this particular question's answer set.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable password authentication and use only key-based authentication.
Disabling password authentication and enforcing key-based authentication eliminates the risk of brute-force password guessing attacks. SSH keys use asymmetric cryptography (RSA, ECDSA, or Ed25519) and are resistant to credential stuffing and dictionary attacks, provided private keys are kept secure. This is a foundational security hardening step recommended by the CIS Benchmarks for Linux.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable root login over SSH.
Why it's wrong here
This is a security best practice but not a method to 'secure SSH access' itself; it limits access but doesn't strengthen authentication.
- ✗
Use FTP over SSH (SFTP) for file transfers.
Why it's wrong here
SFTP is a file transfer protocol, not a method to secure SSH access.
- ✓
Disable password authentication and use only key-based authentication.
Why this is correct
Key-based authentication is much stronger against brute-force and phishing.
- ✗
Require users to change their passwords every 30 days.
Why it's wrong here
Password aging does not prevent brute-force attacks; key-based authentication is recommended.
- ✓
Change the default SSH port from 22 to a non-standard port.
Why this is correct
This reduces the number of automated attacks targeting port 22.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 507 original LPIC-2 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-2 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-2 exam.