EX200 Deploy, configure, and maintain systems Practice Question
A user is unable to log in via SSH. The administrator checks /var/log/secure and sees 'Authentication refused: bad ownership or modes' for the user's home directory. What is the most likely cause?
⚠ Common exam trap
The log message explicitly points to the home directory, not to ~/.ssh/authorized_keys. Students often confuse this with authorized_keys permissions, but the path in the log determines which file/directory is misconfigured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's home directory is owned by root
The error 'Authentication refused: bad ownership or modes' includes the path of the offending file. When the log message references the user's home directory, it means the home directory itself has incorrect ownership or permissions. SSH's StrictModes requires the home directory to be owned by the user and not writable by group or others. If the home directory is owned by root, sshd refuses authentication. The correct answer is D.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The sshd service is not running
Why it's wrong here
If the sshd service were not running, the SSH client would never reach the authentication stage. The TCP connection to port 22 would be refused or time out, producing errors such as 'Connection refused' or 'No route to host', not 'Permission denied (publickey)' or a repeated password prompt. The fact that the user receives an authentication error proves that the server is listening and the SSH handshake is completing, so sshd is definitely running.
- ✗
The SELinux context is wrong
Why it's wrong here
A wrong SELinux context on the user's SSH files would typically cause sshd to fail before any authentication prompt appears. The audit.log would show an AVC denial with a message like 'SELinux is preventing sshd from stat() access on the file authorized_keys'. This usually results in 'Connection closed by remote host' or 'Permission denied' only after a delay, but the log message and behavior differ from the direct strict-modes error about file permissions on .ssh/authorized_keys.
- ✗
The .ssh/authorized_keys file has incorrect permissions
Why it's wrong here
This is the correct diagnosis because sshd explicitly validates the ownership and mode of ~/.ssh and ~/.ssh/authorized_keys during public key authentication. If the authorized_keys file is group-writable, world-writable, or owned by the wrong user, sshd refuses to use it and reports 'Authentication refused: bad ownership or modes for /home/user/.ssh/authorized_keys'. The standard fix is to set the file to 600 and ensure it is owned by the user, then restart the SSH session.
- ✓
The user's home directory is owned by root
Why this is correct
An improperly owned home directory is a different failure point that would prevent the '.' in 'bad ownership or modes for /home/user/.ssh/authorized_keys' from being accurate. When the home directory is owned by root, sshd may either fail to traverse into it (if permissions block the user) or produce a separate StrictModes complaint such as 'Home directory /home/user is not owned by user' or 'Could not open authorized keys'. This would stop the login process at an earlier stage, not specifically point at the authorized_keys file's permissions as the cause.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.