CompTIA Linux+ (XK0-006)SecurityHard

A company's security policy requires that only the users 'admin' and 'deploy' be permitted to log in via SSH to a production server, with all other local accounts denied SSH access even if their passwords are correct. Which sshd_config directive achieves this?

  1. AAllowUsers admin deploy
  2. BPermitRootLogin no
  3. CAuthorizedKeysFile .ssh/authorized_keys
  4. DMatch User admin,deploy
Show answer & explanation

Correct answer: A. AllowUsers admin deploy

The AllowUsers directive in sshd_config restricts SSH login to an explicit whitelist of usernames, denying access to any account not listed, regardless of correct credentials. It must be followed by 'systemctl restart sshd' to take effect.

Why the other options are wrong

  • B. PermitRootLogin no only restricts the root account specifically; it does not limit which non-root users can log in.
  • C. AuthorizedKeysFile specifies where public keys are stored for key-based auth; it does not restrict which users may attempt login.
  • D. Match User is used to conditionally apply configuration blocks based on criteria, not to outright allow/deny login by itself.

SSH AllowUsers Directive

AllowUsers in /etc/ssh/sshd_config restricts SSH logins to an explicit space-separated list of usernames, denying all others regardless of valid credentials.

  • Syntax: AllowUsers user1 user2
  • Can also restrict by host: user@host
  • DenyUsers is the inverse, blacklisting specific accounts
  • Requires sshd restart to take effect

Memory trick: AllowUsers is the VIP guest list — no name, no entry, no matter the password.

More Security questions