SSH (Secure Shell)
SSH (Secure Shell)
Beginner
Q1: What is SSH?
SSH (Secure Shell) is a network protocol used to securely access and manage remote systems over an unsecured network.
Q2: Why is SSH needed?
SSH provides encrypted communication and secure remote authentication, which is safer than telnet and other insecure alternatives.
Q3: What does SSH typically secure?
SSH commonly secures remote terminal access, file transfer, tunneling, and port forwarding.
Q4: What is the default SSH port?
The default SSH port is 22.
Q5: What is the SSH client?
The SSH client is the application that connects to a remote SSH server, such as ssh on Linux or PuTTY on Windows.
Q6: What is the SSH server?
The SSH server is the daemon listening for incoming SSH connections, often sshd.
Q7: What does SSH encrypt?
SSH encrypts the communication channel between the client and the remote server, including terminal sessions and data transfers.
Q8: What is the difference between SSH and SSL/TLS?
SSH is designed mainly for remote shell access and secure command execution. TLS is commonly used for securing HTTP, mail, and other application protocols.
Q9: What is the purpose of a key pair?
A key pair is used to authenticate securely without sending a password over the network.
Q10: What is a private key?
A private key is kept secret on the client machine and used to prove identity.
Q11: What is a public key?
A public key is shared with the server and used to verify the private key without exposing it.
Q12: What is asymmetric encryption?
Asymmetric encryption uses a pair of keys: public and private. Data encrypted with one key can only be decrypted with the other.
Q13: What is authentication in SSH?
Authentication is the process of proving the identity of the client to the server.
Q14: What are common SSH authentication methods?
Common methods include:
- password authentication
- public key authentication
- host-based authentication
- keyboard-interactive authentication
Q15: What is password authentication?
Password authentication sends a password to the server and verifies it against the system account.
Q16: What is public key authentication?
Public key authentication verifies that the client owns a matching private key, without sending a password.
Q17: Why is public key authentication preferred?
It is more secure and more convenient than password login, especially for automation and remote administration.
Q18: What is ssh-agent?
ssh-agent stores private keys in memory so they do not need to be entered repeatedly.
Q19: What is ssh-add?
ssh-add loads private keys into the SSH agent for reuse.
Q20: What is the SSH config file?
The SSH config file allows predefined connection settings such as host aliases, ports, and identity files.
Q21: What is the typical SSH config path?
On Linux/macOS: ~/.ssh/config
Q22: What is known_hosts?
known_hosts stores the host public keys previously seen by the client, helping detect MITM attacks.
Q23: What is host key verification?
Host key verification confirms the server is the same server the client expects, based on known host fingerprints.
Q24: What is a fingerprint?
A fingerprint is a cryptographic hash of a public key used to quickly compare keys.
Q25: What is SSH port forwarding?
SSH port forwarding creates a tunnel that redirects traffic through an encrypted SSH connection.
Q26: What is local port forwarding?
Local port forwarding sends traffic from a local port to a remote destination through the SSH tunnel.
Q27: What is remote port forwarding?
Remote port forwarding sends traffic from a remote SSH server port to a local destination.
Q28: What is dynamic port forwarding?
Dynamic port forwarding uses SSH as a SOCKS proxy for many outgoing connections.
Q29: What is an SSH tunnel?
An SSH tunnel creates a secure communication path between endpoints using SSH as the transport.
Q30: What is SOCKS?
SOCKS is a proxy protocol used by clients to send traffic through a tunnel, often for browsing or application-level routing.
Q31: What is scp?
scp copies files securely between hosts over SSH.
Q32: What is sftp?
sftp provides secure file transfer using the SSH protocol.
Q33: What is rsync over SSH?
rsync can use SSH as the transport for encrypted backup and synchronization.
Q34: What is the SSH command syntax?
A common form is:
ssh user@hostname
Q35: What is the SSH command for a custom port?
Example:
ssh -p 2222 user@host
Q36: What is the command to specify an identity file?
Example:
ssh -i ~/.ssh/id_rsa user@host
Q37: What does -v do in ssh?
It enables verbose output, helping diagnose SSH connection issues.
Q38: What is a key fingerprint check?
It compares the server’s public key fingerprint with a trusted value to verify identity.
Q39: What is the SSH daemon?
The SSH daemon is the service running on the server that accepts incoming client connections.
Q40: What is sshd_config?
sshd_config is the SSH server configuration file.
Q41: What is ssh_config?
ssh_config is the client configuration file.
Q42: What is a remote shell?
A remote shell is a command-line interface opened on a remote machine through SSH.
Q43: What is remote administration?
Remote administration means managing a server through network commands, often over SSH.
Q44: What is passwordless authentication?
Passwordless authentication uses keys instead of passwords for login.
Q45: What is a challenge-response authentication?
A server can challenge the client for proof of possession of a key or credentials without sending a password.
Q46: What is shell escaping?
Shell escaping ensures special characters are correctly passed to the remote shell.
Q47: Why does SSH not send data in plain text?
Because SSH encrypts the session, protecting sensitive credentials and command output.
Q48: What is the SSH protocol family?
SSH is a secure remote access protocol, not to be confused with SFTP or SCP, which are higher-level utilities.
Q49: Can SSH also be used for tunneling databases or web traffic?
Yes. SSH can tunnel app traffic, making it useful for secure access to internal resources.
Q50: What is a bastion host?
A bastion host is a hardened server used as an entry point to a private network.
Q51: Why often use SSH through a bastion host?
It provides controlled access to private environments without exposing all services publicly.
Q52: What is a jump host?
A jump host is another term for a bastion or intermediate host used to reach private servers.
Q53: What is a private key passphrase?
A passphrase protects the private key with an additional encryption layer.
Q54: Why use a passphrase?
It adds another layer of protection if the private key file is stolen.
Q55: What is an SSH agent with passphrase?
The SSH agent can unlock a private key once and reuse it without repeated password prompts.
Q56: What is a shell prompt?
A shell prompt is the command-line interface shown after login.
Q57: What is ssh-keygen?
ssh-keygen generates SSH key pairs.
Q58: What are common key types?
Common SSH key types include:
- RSA
- ED25519
- ECDSA
Q59: Why is ED25519 popular?
It is fast, secure, and efficient, and is widely recommended for modern systems.
Q60: What is an authorizedkeys file?
The authorized_keys file contains public keys allowed to log in to a user account.
Q61: What is the default SSH key location?
By default on Linux/macOS:
/.ssh/id_rsa
or
/.ssh/id_ed25519
Q62: What is the purpose of permission settings on SSH keys?
Proper file permissions prevent unauthorized access to private keys.
Q63: What is the recommended permission for private keys?
Typically 600 (or 400 if stricter).
Q64: What is the typical permission for ~/.ssh directory?
Usually 700.
Q65: What is shell access via SSH?
Shell access means the user can run commands on the remote system through an interactive session.
Q66: What is command execution over SSH?
A non-interactive SSH session can run a single command remotely.
Q67: What is ssh user@host command?
This runs a remote command without opening an interactive shell.
Q68: What is "remote execution"?
Remote execution means running commands on a machine over SSH.
Q69: What is the purpose of SSH in automation?
SSH is widely used by automation tooling to deploy, configure, and manage systems.
Q70: What is SSH in DevOps?
SSH is commonly used to provision servers, run scripts, and orchestrate infrastructure.
Q71: What is the difference between telnet and SSH?
Telnet sends data in clear text; SSH encrypts it.
Q72: Why is telnet considered insecure?
Because credentials and commands can be intercepted.
Q73: What is the use of ssh-copy-id?
ssh-copy-id uploads a public key to a remote server’s authorized keys.
Q74: What is an SSH fingerprint mismatch?
A fingerprint mismatch usually means the server key changed or a MITM attack is occurring.
Q75: What does "remote host identification has changed" mean?
It means the SSH server key on that host differs from the one stored in knownhosts.
Q76: What is the impact of a changed host key?
It may indicate a server rebuild, impersonation attempt, or configuration issue.
Q77: What is the purpose of the SSH server host key?
The host key identifies the server to clients and prevents impersonation.
Q78: What is a server host key pair?
A server has a private host key and a public host key used for SSH identity verification.
Q79: What is the user authentication key?
This is the key pair the user uses to authenticate to the server.
Q80: What is the difference between host keys and user keys?
Host keys identify the server. User keys identify the client.
Q81: What is GSSAPI authentication?
GSSAPI authentication uses Kerberos or similar mechanisms for identity management.
Q82: Why is SSH used for backups?
It provides encrypted transport for remote copy operations and secure automation.
Q83: What is a remote exec command?
Example:
ssh host "uptime"
Q84: What is SSH session multiplexing?
SSH multiplexing reuses an existing SSH connection to run multiple commands more efficiently.
Q85: What is ControlMaster in SSH?
ControlMaster allows multiplexing multiple SSH sessions over one master connection.
Q86: What is X11 forwarding?
X11 forwarding allows a remote graphical application to display locally through SSH.
Q87: Why is X11 forwarding less preferred today?
It has security implications and is less commonly used than remote CLI tools.
Q88: What is SSH tunneling for database access?
You can create a tunnel through SSH to access a database on a private network securely.
Q89: What is reverse SSH?
Reverse SSH connects from a machine behind NAT back to a reachable SSH server, allowing remote access.
Q90: What is secure file transfer?
Secure file transfer means copying files without exposing them to sniffing or tampering.
Q91: What is sftp vs scp?
Both are secure file transfer protocols over SSH.
sftp is more feature-rich and interactive; scp is simpler.
Q92: What is the role of SSH in cloud infrastructure?
SSH is frequently used to access EC2, VM, and container hosts securely.
Q93: What is SSH access to a container?
A container runtime may expose a shell over SSH for remote administration or debugging.
Q94: Why is SSH disabled by default on some systems?
Because it increases attack surface unless properly secured and monitored.
Q95: What is SSH security hardening?
Hardening means limiting access, disabling root login, enforcing key-based auth, and restricting users.
Q96: What is the impact of disabling root login?
It reduces direct administrative attack paths and enforces least privilege.
Q97: What is least privilege?
Least privilege means granting the minimum required permissions to a user or service.
Q98: What is the principle of least privilege in SSH?
Only allow the users who need SSH access and restrict them to required commands or hosts.
Q99: What is a locked-down SSH policy?
A locked-down policy may include:
- key-only auth
- no password login
- no root login
- firewall restrictions
- two-factor authentication
Q100: What is two-factor authentication for SSH?
It requires something you know and something you have, such as a password and a hardware token.
Intermediate
Q101: What is the SSH protocol version?
SSH commonly uses version 2, known as SSH-2, which is the modern secure implementation.
Q102: What is the SSH transport layer?
The SSH transport layer provides encryption, integrity, and host authentication.
Q103: What is the SSH userauth layer?
This layer handles user authentication after the secure transport channel is established.
Q104: What is the SSH connection layer?
The connection layer multiplexes multiple channels, such as shell, SFTP, ports, and forwarding.
Q105: What are SSH channels?
SSH channels are multiplexed logical communication streams over a single connection.
Q106: Why is SSH connection multiplexing valuable?
It allows one SSH connection to carry multiple independent streams efficiently.
Q107: What does ssh -N -L port:host:port user@host do?
It creates a local tunnel without opening an interactive shell.
Q108: What does ssh -R remoteport:host:localport user@host do?
It creates a remote port forwarding tunnel.
Q109: What is the difference between TCP and SSH tunneling?
TCP tunneling wraps TCP traffic inside an SSH connection; SSH is the transport for the tunnel.
Q110: What is port binding?
Port binding creates a listening socket at a local or remote endpoint for forwarded traffic.
Q111: What is local bind address?
It is the address used to listen on local forwarded ports, often 127.0.0.1.
Q112: What is remote bind address?
It is the address used on the remote SSH server for a remote port-forwarded port.
Q113: Why use loopback in tunnels?
Loopback restricts access to the local machine, reducing external exposure.
Q114: What is SOCKS5?
SOCKS5 is a common proxy protocol that supports dynamic port forwarding and authentication.
Q115: What is sshuttle?
sshuttle is a tool that creates VPN-like tunnels through SSH for routing traffic.
Q116: What is the role of ~/.ssh/knownhosts?
It stores trusted server host keys and prevents naive man-in-the-middle attacks.
Q117: How is host key verification protected?
The client compares the host key fingerprint to the stored expected key.
Q118: What is a host key rotation?
Host key rotation means generating a new server host key and updating clients’ known_hosts entries.
Q119: What is SSH key rotation?
SSH key rotation means replacing user or host keys after a compromise or policy change.
Q120: Why rotate SSH keys?
Because stale keys may be exposed or become outdated.
Q121: What is a bastion jump using SSH config?
Example:
Host prod-hop
~ HostName bastion.example.com~
~ User ubuntu~
~ IdentityFile /.ssh/bastion_key
Host prod-server
~ HostName 10.0.0.10~
~ User admin~
~ ProxyJump prod-hop~
Q122: What is ProxyJump?
ProxyJump allows SSH to connect through an intermediate host automatically.
Q123: Why use ProxyCommand?
It allows custom tunneling or jump logic when ProxyJump is insufficient.
Q124: What is SSH agent forwarding?
SSH agent forwarding allows the remote server to use your local SSH agent for further SSH connections.
Q125: What are the security trade-offs of agent forwarding?
It is powerful but can be dangerous if the remote host is compromised.
Q126: How do you disable agent forwarding?
Use:
ssh -A to enable
and omit -A or set ForwardAgent no in config.
Q127: What is the SSH config Host stanza?
It groups connection settings for hosts matching a pattern.
Q128: What is the purpose of StrictHostKeyChecking?
It controls behavior when the host key is unknown or changed.
Q129: What are valid values for StrictHostKeyChecking?
Common values:
- yes
- no
- accept-new
Q130: Why should StrictHostKeyChecking be set to yes in production?
It enforces validation instead of accepting unknown or changed hosts silently.
Q131: What is UserKnownHostsFile?
It specifies a custom file for known host keys.
Q132: What is the purpose of compression in SSH?
Compression reduces payload size, which may help performance for slower links.
Q133: Why is compression sometimes a security concern?
Because it may hide characteristics or add CPU overhead, but it is not usually a major security problem.
Q134: What is SSH session logging?
SSH session logging records connection metadata and terminal output for auditing and troubleshooting.
Q135: What is SSH auditing?
Auditing reviews SSH access, keys, logs, and configuration for security compliance.
Q136: What is SSH access control by user?
You can restrict which users can log in via SSH through minimal ACLs and OS-level permissions.
Q137: What is SSH command restriction?
You can restrict an SSH key to run only a specific command on a remote server.
Q138: What is forced command in authorizedkeys?
The server can define a command that must run after successful key authentication, even if the user requests another command.
Q139: What is a restricted key?
A restricted key is a key that can only perform some permitted operations.
Q140: Why is restricted command use valuable?
It reduces risk when a key is compromised or misused.
Q141: What is SSH key passphrase caching?
It stores a passphrase in the agent to avoid repeated prompts.
Q142: What is an SSH jump box?
A jump box is a machine that a user connects through before reaching more restricted systems.
Q143: What is server-side authentication policy?
Examples:
- disable password login
- require key-based auth
- restrict to selected users
- require MFA
Q144: What is MFA for SSH?
Multi-factor authentication adds another verification step beyond the key or password.
Q145: What is PAM in SSH?
PAM (Pluggable Authentication Modules) allows SSH to integrate with system authentication frameworks.
Q146: What is the role of SELinux or AppArmor with SSH?
They can restrict what the SSH process and users can do after login.
Q147: What is the difference between interactive and non-interactive SSH?
Interactive SSH opens a remote shell. Non-interactive SSH runs one command or script and exits.
Q148: What does SSH use for encryption?
SSH uses symmetric encryption for data and asymmetric crypto for key exchange and authentication.
Q149: What is key exchange?
Key exchange is the process of agreeing on a shared secret used to encrypt the session.
Q150: What is Diffie-Hellman?
Diffie-Hellman is a widely used key exchange algorithm used to establish a shared secret securely.
Q151: What is a symmetric session key?
A symmetric session key is generated and shared by both sides to encrypt traffic after key exchange.
Q152: Why are symmetric keys used for session traffic?
They are faster and more efficient than asymmetric encryption for bulk data.
Q153: What is MAC in SSH?
MAC (Message Authentication Code) ensures integrity and authenticity of transmitted data.
Q154: Why are SSH connections considered secure?
Because they provide confidentiality, integrity, and authenticity.
Q155: What is an SSH session ID?
The session ID is a unique identifier for the authenticated session, used for tracking and debugging.
Q156: What is the SSH channel open/close lifecycle?
A client opens a channel, performs traffic, then closes it when done.
Q157: What is a shell session?
A shell session is the interactive remote terminal.
Q158: What is remote execution from CI pipelines?
CI systems often use SSH to deploy services or run scripts on remote machines.
Q159: What is command injection risk in SSH?
If commands are not properly escaped, harmful remote commands can execute.
Q160: Why should scripts avoid passing user input directly to SSH commands?
Because user input may contain shell metacharacters or unintended commands.
Q161: What is SSH escaping in shell syntax?
It ensures strings are interpreted literally and not as shell code.
Q162: What is a secure remote admin model?
It means using minimal privilege, strong identity, monitored access, and encrypted channels.
Q163: What is remote management of Linux machines?
SSH is the standard method for remote Linux system administration.
Q164: What is privileged access management?
It is a framework for controlling who can access sensitive systems and what they may do.
Q165: What is sshdconfig PermitRootLogin?
This directive controls whether root logins are allowed over SSH.
Q166: What is PasswordAuthentication in sshdconfig?
This controls whether password-based SSH login is allowed.
Q167: What is PubkeyAuthentication in sshdconfig?
This controls whether public key authentication is enabled.
Q168: What is X11Forwarding?
This forwards GUI windows for remote applications through SSH.
Q169: What does AllowUsers do?
AllowUsers restricts SSH access to a specific set of usernames.
Q170: What does DenyUsers do?
DenyUsers blocks SSH access for specific users.
Q171: What does AllowGroups do?
AllowGroups restricts SSH logins to members of selected groups.
Q172: What does PermitEmptyPasswords do?
This defines whether empty passwords may be used; it should usually be disabled.
Q173: What is port knocking?
Port knocking is a technique to hide a service by making it appear only after a sequence of connection attempts.
Q174: Why is SSH often used with firewall rules?
To restrict access to only trusted IPs, VLANs, or bastion hosts.
Q175: What is host allow list?
A host allow list is a list of clients or subnets allowed to connect to SSH.
Q176: What is a jump host pattern?
Use a bastion host to enter private networks, then SSH from there to internal servers.
Q177: Why is SSH not a complete security solution by itself?
Because configuration, user management, key hygiene, and network controls are equally important.
Q178: What is the risk of reusing SSH keys across systems?
If one system is compromised, the attacker may access multiple systems.
Q179: What is a proper SSH key hygiene policy?
- unique keys per system or purpose
- short key lifetimes
- regular rotation
- revocation policies
- safe storage
Q180: What is the purpose of revoking keys?
Revocation invalidates compromised or stale credentials.
Advanced / Expert
Q181: What are modern SSH cryptographic algorithms?
Modern SSH uses strong algorithms like:
- curve25519-sha256
- chacha20-poly1305
- aes-256-gcm
- Ed25519 keys
Q182: Why is ED25519 preferred?
It offers strong security with good performance and compact keys.
Q183: What is the role of the KEX algorithm?
KEX (Key Exchange) establishes the shared session secret securely.
Q184: What is the role of the cipher algorithm?
The cipher encrypts the actual session payload.
Q185: What is the role of the MAC algorithm?
The MAC ensures message integrity and authentication.
Q186: What is the difference between integrity and confidentiality?
Confidentiality hides the content. Integrity ensures data was not modified.
Q187: How does SSH verify message integrity?
It uses MACs over encrypted packets.
Q188: What is CBC mode and why is it avoided in SSH?
Some CBC-based encryption modes are susceptible to padding oracle and side-channel issues; modern SSH uses better authenticated modes.
Q189: Why are authenticated encryption modes preferred?
They provide confidentiality and integrity simultaneously while reducing implementation errors.
Q190: What is post-quantum cryptography?
Post-quantum cryptography refers to cryptographic algorithms designed to be resistant to quantum attacks.
Q191: Is SSH impacted by quantum computing?
It may be eventually affected, so migrations to quantum-resistant algorithms may matter in the future.
Q192: What is the risk of weak key exchange?
Weak key exchange can allow passive attackers to recover session secrets in some attack models.
Q193: What is a timing attack?
A timing attack exploits differences in execution time to infer secret information.
Q194: How does SSH reduce timing exposure?
By using well-hardened libraries and constant-time operations where relevant.
Q195: What is host key pinning?
Host key pinning ensures a client trusts a specific host key or set of keys instead of just any matching key.
Q196: What is a MITM attack?
A man-in-the-middle attack intercepts communication between the client and server and impersonates each side.
Q197: How does SSH prevent MITM attacks?
It verifies server host keys against known trusted values.
Q198: What is key trust establishment?
Trust establishment means verifying an SSH public key is authentic and belongs to the intended server or user.
Q199: What are cryptographic libraries used by SSH?
OpenSSH is the most common, but many libraries and clients implement SSH using robust cryptographic primitives.
Q200: Why is SSH considered fundamental to secure infrastructure?
Because it is one of the main secure administrative channels for servers, devices, and remote systems in modern infrastructure.
Q201: What is the main challenge in SSH hardening?
Balancing operational convenience against security policy, without creating friction or breaking automation.
Q202: What is secure remote access architecture?
A secure remote access architecture often includes:
- bastion hosts
- user keys only
- no root login
- MFA
- logging and alerting
- source IP restrictions
Q203: What is SSH privilege separation?
Privilege separation isolates the privileged SSH process from user session execution to reduce impact if it is compromised.
Q204: What is chroot jail in SSH?
A chroot jail can isolate a user session to a restricted filesystem.
Q205: What is SSH lockdown in enterprise environments?
SSH lockdown often includes centralized identity providers, key management, MFA, and controlled auditing.
Q206: What is SSH key management?
SSH key management includes generation, storage, rotation, distribution, revocation, and auditing.
Q207: Why centralize SSH key management?
Centralization reduces key sprawl, makes rotation manageable, and improves auditability.
Q208: What is passwordless access and why is it attractive?
Passwordless login improves security and automation but requires careful key handling and monitoring.
Q209: What is SSH access via identity provider?
Some enterprises integrate SSH with LDAP, Kerberos, or IAM systems to centralize access control.
Q210: What is least privilege in SSH administration?
It means only allowing the exact users and commands needed for a role, not broad unrestricted shell access.
Q211: What is SSH session recording?
Recording terminal sessions provides accountability and helps with security investigations.
Q212: Why is auditing SSH sessions important?
Because administrative access is high risk and should be traceable.
Q213: What are common SSH misconfigurations?
Examples:
- password login enabled
- root login allowed
- weak algorithms enabled
- too-broad authorizedkeys permissions
- open SSH to the internet without IP restrictions
Q214: What is the security impact of allowing password SSH?
It raises risk of credential guessing, brute-force attacks, and password leakage.
Q215: Why is brute-force common against SSH?
Because port 22 is exposed on many internet-connected systems and attackers scan continuously.
Q216: What is fail2ban?
fail2ban can block clients after repeated failed SSH login attempts.
Q217: How do hardened SSH setups guard against brute force?
By disabling passwords, restricting users, using firewalls, and limiting login sources.
Q218: What is a honeypot in SSH context?
An SSH honeypot is a decoy system designed to attract attackers and collect evidence.
Q219: What is a layered security model for SSH?
It combines access restrictions, strong auth, network segmentation, and auditing.
Q220: Why is SSH still central after decades?
Because it remains the most reliable and secure standard for remote machine administration and automation.
Q221: What is the future of SSH?
The future brings stronger defaults, stricter policies, better key management, and continued integration with identity and policy systems.
Q222: What is the main engineering lesson in SSH?
Remote access is a critical trust boundary. SSH must be designed with strong authentication, least privilege, and careful monitoring.