CompTIA Linux+ (XK0-006)SecurityHard
A user needs to quickly encrypt a single file, notes.txt, for personal storage on a USB drive using a shared passphrase rather than public-key cryptography, so that anyone who knows the passphrase can later decrypt it. Which command should the user run?
- Agpg --encrypt --recipient user@example.com notes.txt
- Bgpg --gen-key notes.txt
- Cgpg -c notes.txt
- Dgpg --sign notes.txt
Show answer & explanationAnswer & explanation
Correct answer: C. gpg -c notes.txt
The -c (or --symmetric) flag tells GPG to use symmetric encryption, prompting for a passphrase and using a cipher such as AES256 to encrypt the file into notes.txt.gpg; anyone with the passphrase can decrypt it with gpg -d. Asymmetric encryption (--recipient) instead requires the recipient's public/private key pair.
Why the other options are wrong
- A. This performs asymmetric encryption to a specific recipient's public key, requiring their private key to decrypt, not a shared passphrase.
- B. --gen-key generates a new GPG key pair; it does not accept a filename argument to encrypt.
- D. --sign creates a digital signature for authenticity/integrity, it does not encrypt the file's contents.
GPG Symmetric Encryption
GPG's -c (--symmetric) option encrypts a file using a single shared passphrase and a symmetric cipher (default AES256), suitable when no recipient key exchange is needed.
- gpg -c file encrypts using a passphrase (symmetric)
- gpg -d file.gpg decrypts using the same passphrase
- Differs from --encrypt --recipient, which uses asymmetric public/private keys
- Default cipher is AES256 unless --cipher-algo specifies otherwise
Memory trick: '-c' for 'code word' — one shared secret unlocks it for everyone who knows it.