CompTIA Linux+ (XK0-006)SecurityMedium
An administrator generated a GPG key pair for signing important documents. As a best practice in case the private key is ever lost or compromised, which action should be taken immediately after key generation?
- ARun 'gpg --export-secret-keys' and email the output to a personal backup address
- BRun 'gpg --gen-revoke' to create a revocation certificate and store it securely offline
- CDelete the private key and keep only the public key
- DSet the key's expiration date to 'never expires'
Show answer & explanationAnswer & explanation
Correct answer: B. Run 'gpg --gen-revoke' to create a revocation certificate and store it securely offline
A revocation certificate allows the key owner to publish a notice invalidating the key pair if it is lost, stolen, or compromised, without needing access to the private key itself. It should be generated immediately and stored securely offline, separate from the key.
Why the other options are wrong
- A. Emailing a secret key export is a serious security risk and exposes the private key to interception.
- C. Deleting the private key would make the key pair unusable for signing or decrypting entirely.
- D. Never expiring is unrelated to revocation and doesn't provide any recovery mechanism if the key is compromised.
GPG Revocation Certificate
A revocation certificate is a pre-generated file that lets a key owner publicly invalidate their GPG key pair if it is lost or compromised, created with gpg --gen-revoke.
- Should be generated right after key creation, not after compromise
- Stored offline/securely, separate from the private key
- Once imported and published, marks the key as revoked to others
Memory trick: Revocation cert = the emergency 'kill switch' made in advance.