CompTIA Linux+ (XK0-006)SecurityMedium

A user needs to send a confidential file called payroll.csv to a colleague such that only the colleague, who has shared their public key, can decrypt and read it. Which command correctly encrypts the file using GPG for that specific recipient?

  1. Agpg --gen-key payroll.csv
  2. Bgpg --symmetric payroll.csv
  3. Cgpg --encrypt --recipient colleague@example.com payroll.csv
  4. Dgpg --sign payroll.csv
Show answer & explanation

Correct answer: C. gpg --encrypt --recipient colleague@example.com payroll.csv

gpg --encrypt --recipient uses the recipient's imported public key to asymmetrically encrypt the file, producing payroll.csv.gpg, which only the holder of the matching private key can decrypt.

Why the other options are wrong

  • A. --gen-key generates a new GPG keypair; it does not operate on or encrypt an existing file.
  • B. --symmetric encrypts using a shared passphrase rather than the recipient's public key, requiring separate secure passphrase distribution.
  • D. --sign only creates a digital signature to prove authenticity; it does not encrypt the content.

GPG Asymmetric Encryption

GPG can encrypt data for a specific recipient using their imported public key; only the corresponding private key can decrypt the resulting ciphertext.

  • gpg --encrypt --recipient <keyid/email> file
  • Recipient's public key must be imported and trusted first
  • Output is file.gpg by default
  • Use --decrypt with the private key to read the file back

Memory trick: Public key locks the mailbox; only the private key opens it.

More Security questions