Jump server

A hardened, closely monitored host that administrators connect to first and from which they reach systems in a protected zone, giving one controlled path for administrative access.

A jump server, also called a jump host or jump box, is a hardened system at the boundary of a protected network segment that acts as the approved route for administrative access into it. Administrators authenticate to the jump server first, commonly with multi-factor authentication, and only from there open sessions, typically over SSH or RDP, to the servers and network devices they manage. Systems inside the zone are configured to accept administrative connections from the jump server and refuse them from elsewhere.

Concentrating access in one place makes it easier to enforce least privilege, record sessions and review who did what. It also concentrates risk: a compromised jump server is a path to everything behind it, so it is kept minimal, patched and monitored, and is often paired with just-in-time access. The term overlaps with bastion host, a hardened system exposed to an untrusted network; a jump server’s defining role is to broker administrative sessions into a protected zone. It also differs from out-of-band management, which separates the path rather than the entry point, though the two are often combined.

Exam relevance: a scenario is likely to ask how to control and audit administrator access to a sensitive segment. Candidates are expected to recognise the jump server and its main weakness: it becomes a high-value target.