1. Edit the config so it includes ALL of: PermitRootLogin no, PasswordAuthentication no, Protocol 2, PermitEmptyPasswords no, X11Forwarding no, MaxAuthTries 3. Why: each disables a common foothold (remote root brute force, password guessing, legacy protocol, empty passwords, X11 pivoting, unlimited guesses).
2. Paste the full config into the box and submit; when the checker finds every required directive the flag is returned.
Lesson: harden by disabling defaults you don't need and enforcing key-based auth.