Problem Statement
Which SSH configuration is a widely recommended hardening step on Linux servers?
Explanation
Disabling direct root login reduces brute-force risk and audit ambiguity. Key-based authentication is stronger than passwords and enables MFA add-ons. Combine with allowlists, modern ciphers, and fail2ban or equivalent.
Code Solution
SolutionRead Only
In /etc/ssh/sshd_config: PermitRootLogin no PasswordAuthentication no PubkeyAuthentication yes
