CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security auditor is reviewing the hardening configuration of a Linux server that hosts a critical web application. The auditor discovers that the server's SSH service is configured to allow direct root login and uses password-based authentication. Which of the following recommendations would SIGNIFICANTLY improve the server's security posture against brute-force attacks and unauthorized access?

  1. AImplement a firewall rule to block all incoming SSH traffic from outside the internal network.
  2. BInstall an Intrusion Detection System (IDS) on the server to monitor SSH login attempts.
  3. CDisable direct root login via SSH and enforce key-based authentication for all users.
  4. DIncrease the password complexity requirements for all user accounts.
Show answer & explanation

Correct answer: C. Disable direct root login via SSH and enforce key-based authentication for all users.

Disabling direct root login prevents attackers from directly targeting the most privileged account. Enforcing key-based authentication eliminates the risk of brute-forcing passwords, as cryptographic keys are much harder to compromise than passwords.

Why the other options are wrong

  • A. Blocking external SSH is a good network-level control, but it doesn't address the vulnerability if an attacker gains internal network access or if SSH must be accessible from certain external points.
  • B. An IDS can detect brute-force attempts, but it's a detection mechanism, not a preventative control that stops the attack vector itself like key-based authentication does.
  • D. While good practice, increasing password complexity still leaves the system vulnerable to brute-force attacks against the root account, especially if it's exposed.

SSH Hardening

The process of securing the Secure Shell (SSH) service to protect against unauthorized access and attacks.

  • Disable root login.
  • Use key-based authentication.
  • Limit user access and monitor logs.

Memory trick: SSH keys are better than roots and passwords.

More Security Engineering questions