EX200 Create simple shell scripts Practice Question
An organization uses a shell script that runs daily via cron on a central management server to archive logs from 50 remote Red Hat Enterprise Linux servers. The script uses `scp` with SSH key-based authentication (passwordless) to transfer files. Recently, after a security team rotated the SSH host keys on all remote servers, the script started failing with 'Host key verification failed' errors. The administrator needs to restore automated log transfers without compromising security. The remote servers are in a controlled internal network, and the management server's `~/.ssh/known_hosts` file is not centrally managed. Which course of action should the administrator take?
⚠ Common exam trap
A common mix-up: candidates think disabling host key checking (Option A) is an acceptable quick fix, but the RHCSA exam expects understanding that `StrictHostKeyChecking=no` is a security risk and that the correct approach is to update the `known_hosts` file with the new keys using `ssh-keyscan`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use ssh-keyscan to retrieve the new host keys and add them to the management server's known_hosts file.
Using `ssh-keyscan` to retrieve the new host keys and add them to the management server's `known_hosts` file is the proper method to update host keys without disabling security. This approach maintains SSH host key verification, which prevents man-in-the-middle attacks, while allowing the script to authenticate the remote servers after the key rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the -o StrictHostKeyChecking=no option to the scp command in the script.
Why it's wrong here
Adding -o StrictHostKeyChecking=no to the scp command tells the SSH client to accept any host key without verifying it against known_hosts. While this silences the host key verification failure, it also removes protection against man-in-the-middle attacks because the client will trust any server that presents itself as the target. The script would run, but the underlying trust problem remains unresolved: the correct approach is to securely update known_hosts with the server's legitimate new host key.
- ✓
Use ssh-keyscan to retrieve the new host keys and add them to the management server's known_hosts file.
Why this is correct
This answer correctly re-establishes trust by fetching the remote server's current public host keys with ssh-keyscan and appending them to the management server's known_hosts file. After this update, scp will find the new host key for that server and pass verification, allowing the cron job to run normally. To preserve security, the administrator should verify the retrieved fingerprints out-of-band (for example, by comparing the server's SSH host key fingerprint from the console) before adding them, because blindly accepting keys could still allow man-in-the-middle attacks.
- ✗
Modify the sshd_config on each remote server to disable host key checking.
Why it's wrong here
Modifying sshd_config on the remote servers is ineffective because host key checking is a client-side operation; the SSH client compares the server's presented host key with entries in the client's known_hosts file. sshd_config controls the SSH server, not the client, and there is no server-side directive that disables client-side host key verification. Even if such a directive existed, it would not update the management server's known_hosts, so the scp command would continue to encounter the same host key mismatch.
- ✗
Replace scp with rsync in the script, as rsync uses a different authentication method.
Why it's wrong here
rsync, when used over SSH (the default when a remote host is specified), uses the same SSH transport and the same host key verification as scp, so it will fail with the same host key mismatch error. The authentication method and trust model are identical: the SSH client must still authenticate the server's host key against known_hosts before establishing the encrypted channel. Replacing scp with rsync does not change the need to update the known_hosts file on the management server.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.