Configuring the IgnoreUserKnownHosts setting for the SSH daemon provides additional assurance that remote login via SSH will require a password, even in the event of misconfiguration elsewhere.
Check
Verify the SSH daemon does not allow known hosts authentication with the following command: