CompTIA Linux+ (XK0-006)SecurityEasy

A developer wants to generate a new SSH key pair using the modern Ed25519 algorithm, which offers strong security with smaller key sizes compared to RSA. Which command should the developer run?

  1. Assh-copy-id -t ed25519
  2. Bssh-keygen -t rsa -b 4096
  3. Cssh-keygen -t ed25519
  4. Dssh-add -t ed25519
Show answer & explanation

Correct answer: C. ssh-keygen -t ed25519

ssh-keygen -t ed25519 generates an Ed25519 key pair, typically saved to ~/.ssh/id_ed25519 and id_ed25519.pub. ssh-copy-id and ssh-add do not create keys; they distribute or cache existing keys.

Why the other options are wrong

  • A. ssh-copy-id installs an existing public key on a remote host; it doesn't generate keys.
  • B. This generates an RSA key pair, not Ed25519.
  • D. ssh-add loads existing private keys into ssh-agent; it doesn't generate keys.

SSH Key Generation

ssh-keygen creates public/private key pairs for SSH authentication; the -t flag selects the algorithm such as rsa, ecdsa, or ed25519.

  • Default output: ~/.ssh/id_<type> and id_<type>.pub
  • Ed25519 offers strong security with a compact 256-bit key
  • ssh-copy-id deploys the public key to a remote authorized_keys file
  • Private keys should have permissions 600

Memory trick: 'Keygen' generates, 'copy-id' delivers, 'add' remembers.

More Security questions