CompTIA Linux+ (XK0-006)SecurityEasy
A security auditor needs to restrict SSH access to a Linux server so that only users from a specific IP address range (192.168.1.0/24) can connect. Which of the following directives in the SSH daemon configuration file (sshd_config) should be used to achieve this?
- AAllowGroups sshusers
- BAllowTcpForwarding no
- CPermitRootLogin no
- DAllowUsers user1 user2
Show answer & explanationAnswer & explanation
Correct answer: D. AllowUsers user1 user2
To restrict SSH access based on IP address range, the AllowUsers directive can be combined with a host pattern. This allows specifying users and their allowed source IP addresses.
Why the other options are wrong
- A. This directive restricts access based on group membership, not source IP addresses.
- B. This directive disables TCP forwarding, which is unrelated to source IP address restrictions for connection.
- C. This directive controls whether the root user can log in via SSH, not IP-based restrictions.
SSH AllowUsers Directive
The AllowUsers directive in sshd_config restricts SSH access to specified users and can include host patterns for IP-based filtering.
- Can specify user@host patterns.
- Host can be an IP address, hostname, or CIDR range.
- If specified, users not listed are denied SSH access.
Memory trick: SSH access: Who, Where, How.