You connect from your workstation to bastion, and from there onward to db01, which trusts the same public key. The private key must not be copied onto bastion. Which option on the first connection makes the onward login work?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct ssh -A user@bastion

Correct. -A forwards the connection to your local ssh-agent. bastion gets a socket named by SSH_AUTH_SOCK through which signing requests travel back to your workstation, so the private key itself never leaves it.

Not correct ssh -X user@bastion

Wrong. -X forwards the X11 display so remote graphical programs can be shown locally. It has no bearing on authentication.

Not correct ssh -f user@bastion

Wrong. -f puts ssh into the background just before command execution, which is used with long-lived tunnels. It forwards nothing.

Not correct ssh -t user@bastion

Wrong. -t forces allocation of a pseudo-terminal, which matters when running an interactive program through a remote command. It does not make any key available on bastion.

Why

Agent forwarding, -A on the command line or ForwardAgent yes in ssh_config, extends the agent's socket to the remote session so that only signature operations, never the key material, cross the link. The cost is that anyone who can read that socket on bastion, including root, can use your key for as long as the session lasts, which is why ProxyJump, ssh -J user@bastion user@db01, is usually preferred for plain hopping: bastion only relays the encrypted session and never sees the agent at all.

Where this comes from

Cited
manual page ssh(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500