Courseiva
Manage security →hardMultiple Select

EX200 Manage security Practice Question

Which TWO methods are considered best practices for securing SSH access to a server? (Select exactly two.)

⚠ Common exam trap

Red Hat often tests the misconception that changing the default SSH port (option D) is a legitimate security measure, but in the EX200 exam, security through obscurity is never considered a best practice—only controls that enforce authentication and authorization are accepted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable root login by setting PermitRootLogin no.

Disabling root login by setting `PermitRootLogin no` in `/etc/ssh/sshd_config` prevents direct SSH access as the root user, forcing administrators to log in as a regular user and then use `sudo` or `su` to escalate privileges. This reduces the attack surface by eliminating a high-value target for brute-force attacks and ensures all actions are auditable via the regular user's session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable root login by setting PermitRootLogin no.

    Why this is correct

    Setting PermitRootLogin no in /etc/ssh/sshd_config blocks direct SSH logins as the root user. This forces administrators to authenticate as an unprivileged account and then use sudo, which provides an auditable trail of privileged commands. Since root has unrestricted access to the entire system, removing direct root SSH access significantly reduces the risk of attackers obtaining full control through a single root credential compromise.

  • ✗

    Use only password authentication for simplicity.

    Why it's wrong here

    Password-only authentication relies on the entropy of the password and is inherently vulnerable to online brute-force attacks, dictionary attacks, and credential stuffing, especially when users choose weak or reused passwords. SSH requires the server to verify the password over the network, but an attacker can attempt unlimited guesses unless throttled by tools like fail2ban. Additionally, passwords offer no cryptographic proof of the client's identity beyond the shared secret, making them far less resilient than asymmetric key pairs.

  • ✓

    Use key-based authentication with passphrase-protected keys.

    Why this is correct

    Key-based authentication uses a private/public key pair, where the private key never leaves the client and is not transmitted over the network, making it highly resistant to interception and brute-force guessing. Adding a passphrase to the private key protects the key at rest, so even if the key file is stolen, the attacker cannot use it without the passphrase. This creates a multi-factor situation—possession of the key file and knowledge of the passphrase—while the server only verifies a cryptographic challenge signed by the client's private key.

  • ✗

    Change the default SSH port to a high-numbered port.

    Why it's wrong here

    Changing the default SSH port to a high-numbered port only provides security through obscurity, which is not considered a real security control. Automated scanners can easily discover listening SSH daemons on any port, and the change does nothing to prevent authentication attacks or exploitation of SSH vulnerabilities. In fact, operating on a non-standard port may break firewall rules, confuse audits, and give a false sense of safety while leaving the underlying authentication mechanisms unchanged.

  • ✗

    Allow SSH access for all users in the system.

    Why it's wrong here

    Allowing SSH access for all system users unnecessarily enlarges the attack surface, as every user account becomes a potential entry point. Many accounts may have weak passwords, be unused, or belong to services that are not meant for interactive login, providing attackers with more targets for brute-force attacks. Restricting SSH access to specific users or groups via AllowUsers, AllowGroups, or a PAM policy ensures that only trusted accounts can attempt authentication.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.