CompTIA Linux+ (XK0-006)SecurityHard

A user needs to quickly encrypt a single file, notes.txt, for personal storage on a USB drive using a shared passphrase rather than public-key cryptography, so that anyone who knows the passphrase can later decrypt it. Which command should the user run?

  1. Agpg --encrypt --recipient user@example.com notes.txt
  2. Bgpg --gen-key notes.txt
  3. Cgpg -c notes.txt
  4. Dgpg --sign notes.txt
Show answer & explanation

Correct answer: C. gpg -c notes.txt

The -c (or --symmetric) flag tells GPG to use symmetric encryption, prompting for a passphrase and using a cipher such as AES256 to encrypt the file into notes.txt.gpg; anyone with the passphrase can decrypt it with gpg -d. Asymmetric encryption (--recipient) instead requires the recipient's public/private key pair.

Why the other options are wrong

  • A. This performs asymmetric encryption to a specific recipient's public key, requiring their private key to decrypt, not a shared passphrase.
  • B. --gen-key generates a new GPG key pair; it does not accept a filename argument to encrypt.
  • D. --sign creates a digital signature for authenticity/integrity, it does not encrypt the file's contents.

GPG Symmetric Encryption

GPG's -c (--symmetric) option encrypts a file using a single shared passphrase and a symmetric cipher (default AES256), suitable when no recipient key exchange is needed.

  • gpg -c file encrypts using a passphrase (symmetric)
  • gpg -d file.gpg decrypts using the same passphrase
  • Differs from --encrypt --recipient, which uses asymmetric public/private keys
  • Default cipher is AES256 unless --cipher-algo specifies otherwise

Memory trick: '-c' for 'code word' — one shared secret unlocks it for everyone who knows it.

More Security questions