SSH File Transfer Protocol (SFTP)
A file transfer and file management protocol that runs as a subsystem of SSH, so commands, credentials and file contents all travel inside one encrypted SSH connection.
SSH File Transfer Protocol moves and manages files inside an SSH connection. SSH supplies the encryption, the integrity protection and the server authentication; SFTP adds the file operations on top, such as upload, download, listing, renaming, deleting and setting permissions. Because everything travels through one SSH session, commonly on TCP port 22, it crosses firewalls more simply than protocols that open separate data connections. It was specified in IETF Internet-Drafts that never became a published RFC, yet it is widely implemented.
The name is the main trap. SFTP is not FTP run through SSH; it is a separate protocol with its own design. It is also different from FTPS, which is the original FTP protected by TLS and keeps FTP’s separate control and data channels. Both protect credentials and data in transit, which plain FTP does not. The letters SFTP were also used much earlier for an unrelated Simple File Transfer Protocol (RFC 913), which is rarely met today. SCP, an older SSH copy tool, offers fewer file functions.
Exam relevance: a scenario may ask for a secure replacement for FTP in an environment that already uses SSH, or offer SFTP and FTPS as competing answers. Candidates are expected to keep straight which of the two runs over SSH and which one over TLS.