CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security auditor is reviewing the hardening configuration of a Linux server that hosts a critical web application. The auditor discovers that the server's SSH service is configured to allow direct root login and uses password-based authentication. Which of the following recommendations would SIGNIFICANTLY improve the server's security posture against brute-force attacks and unauthorized access?
- AImplement a firewall rule to block all incoming SSH traffic from outside the internal network.
- BInstall an Intrusion Detection System (IDS) on the server to monitor SSH login attempts.
- CDisable direct root login via SSH and enforce key-based authentication for all users.
- DIncrease the password complexity requirements for all user accounts.
Show answer & explanationAnswer & explanation
Correct answer: C. Disable direct root login via SSH and enforce key-based authentication for all users.
Disabling direct root login prevents attackers from directly targeting the most privileged account. Enforcing key-based authentication eliminates the risk of brute-forcing passwords, as cryptographic keys are much harder to compromise than passwords.
Why the other options are wrong
- A. Blocking external SSH is a good network-level control, but it doesn't address the vulnerability if an attacker gains internal network access or if SSH must be accessible from certain external points.
- B. An IDS can detect brute-force attempts, but it's a detection mechanism, not a preventative control that stops the attack vector itself like key-based authentication does.
- D. While good practice, increasing password complexity still leaves the system vulnerable to brute-force attacks against the root account, especially if it's exposed.
SSH Hardening
The process of securing the Secure Shell (SSH) service to protect against unauthorized access and attacks.
- Disable root login.
- Use key-based authentication.
- Limit user access and monitor logs.
Memory trick: SSH keys are better than roots and passwords.