SSH always sets up an encrypted connection between the remote and client machine. With the established connection, a shell is created. It works the same way as it does when you're locally logged on to the remote server.
The first time you connect to the remote server, SSH prompts you with a window, asking you to accept the server's host key. If it's your first time connecting to the server, this is normal. But if you've been connecting to an SSH server for a while and you suddenly see the message The authenticity of host 'wintel01 (10.7.2.204)' can't be established. ECDSA key fingerprint is SHA256:2GnYAODZGB+UEuJjuSXrpgOP3gP4xI+rGCtCWfcvHbc. Are you sure you want to continue connecting (yes/no)?, you might want to ...