Courseiva
Manage security →mediumMultiple Choice

EX200 Manage security Practice Question

An administrator wants to allow user 'alice' to SSH into the server using key-based authentication only. Which configuration change is required?

⚠ Common exam trap

Many candidates think disabling password authentication alone is sufficient for key-based access, but they forget that the public key must be placed in the correct location and that `PubkeyAuthentication` must be explicitly enabled if it was previously disabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add alice's public key to ~alice/.ssh/authorized_keys and set PubkeyAuthentication yes in sshd_config.

SSH key-based authentication requires the user's public key to be placed in the user's `~/.ssh/authorized_keys` file, and the SSH daemon must have `PubkeyAuthentication yes` set in `/etc/ssh/sshd_config` to allow public key authentication. This configuration ensures that only users with the corresponding private key can authenticate as 'alice'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add alice's public key to ~alice/.ssh/authorized_keys and set PubkeyAuthentication yes in sshd_config.

    Why this is correct

    Alice's public key is placed in ~alice/.ssh/authorized_keys, and the sshd server verifies that alice possesses the matching private key by sending a challenge that requires a signature. Setting PubkeyAuthentication yes in sshd_config (or confirming it is uncommented, as it defaults to yes) explicitly enables this key-based login mechanism. This is the proper, secure way to allow alice to authenticate without a password.

  • ✗

    Add alice's private key to /etc/ssh/authorized_keys.

    Why it's wrong here

    The server never reads private keys from /etc/ssh/authorized_keys; it expects a public key in a per-user authorized_keys file, typically ~user/.ssh/authorized_keys. Placing a private key there would expose alice's secret key to anyone with read access and is a severe security violation. Additionally, /etc/ssh/authorized_keys is not a standard location or filename for user-authorization data, so sshd would simply ignore it or fail to authenticate alice.

  • ✗

    Set PasswordAuthentication no in /etc/ssh/sshd_config and restart sshd.

    Why it's wrong here

    Setting PasswordAuthentication no only instructs sshd to refuse password-based logins; it does not by itself add any public key or configure certificate-based authentication for alice. Without creating ~alice/.ssh/authorized_keys and adding her public key (and ensuring PubkeyAuthentication is enabled), alice will have no valid authentication method and will be locked out. Restarting sshd merely applies the new passwordless policy; it does not generate or install any keys.

  • ✗

    Set PermitRootLogin prohibit-password.

    Why it's wrong here

    The PermitRootLogin prohibit-password directive applies exclusively to the root account, controlling whether root may log in only with a key and not a password. It has no effect on a regular user such as alice, whose access is governed by the user-specific authorized_keys file and general sshd authentication settings. Configuring this option neither adds alice's key nor adjusts any policy that would permit alice to ssh in.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.