CompTIA Linux+ (XK0-006)SecurityEasy

A company's security policy requires that root never be able to log in directly over SSH; all administrators must log in with their own accounts and use sudo. Which configuration change in /etc/ssh/sshd_config enforces this policy?

  1. AAllowUsers root
  2. BProtocol 2
  3. CPasswordAuthentication no
  4. DPermitRootLogin no
Show answer & explanation

Correct answer: D. PermitRootLogin no

PermitRootLogin no in /etc/ssh/sshd_config prevents the root account from logging in directly via SSH, forcing administrators to authenticate as themselves and use sudo for elevated tasks. The sshd service must be restarted after the change.

Why the other options are wrong

  • A. AllowUsers root would actually explicitly permit root to log in, the opposite of the requirement.
  • B. Protocol 2 forces the more secure SSH protocol version but has nothing to do with root login.
  • C. PasswordAuthentication no disables password logins for all users, but does not specifically block root.

SSH Root Login Restriction

PermitRootLogin controls whether the root account can authenticate directly via SSH; setting it to 'no' enforces least-privilege administration.

  • Located in /etc/ssh/sshd_config
  • Restart sshd after changes: systemctl restart sshd
  • Values: yes, no, prohibit-password, forced-commands-only
  • Best practice pairs this with sudo for privileged tasks

Memory trick: Root stays home—PermitRootLogin no locks the front door to root.

More Security questions