🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An organization uses a public AWS Linux bastion host for administrators worldwide. Security policy states that no long-term credentials may reside on user laptops, and remote shell sessions must remain confidential and tamper-proof when crossing the Internet. Which SSH configuration approach best meets these requirements while minimizing ongoing administrative overhead?

  • Issue each administrator a long-lived 4096-bit RSA key pair, store private keys on their laptops, and disable password authentication.

  • Replace SSH with Telnet tunneled through an SSL VPN terminated on the bastion to gain end-to-end encryption.

  • Configure the bastion to accept only SSH protocol 2 and require authentication with short-lived, CA-signed user certificates issued on demand; disable password and static key logins.

  • Permit SSH protocol 1 but enforce complex passwords and enable fail2ban to block repeated login attempts.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot