CompTIA Linux+ (XK0-006)SecurityMedium
A user needs to send a confidential file called payroll.csv to a colleague such that only the colleague, who has shared their public key, can decrypt and read it. Which command correctly encrypts the file using GPG for that specific recipient?
- Agpg --gen-key payroll.csv
- Bgpg --symmetric payroll.csv
- Cgpg --encrypt --recipient colleague@example.com payroll.csv
- Dgpg --sign payroll.csv
Show answer & explanationAnswer & explanation
Correct answer: C. gpg --encrypt --recipient colleague@example.com payroll.csv
gpg --encrypt --recipient uses the recipient's imported public key to asymmetrically encrypt the file, producing payroll.csv.gpg, which only the holder of the matching private key can decrypt.
Why the other options are wrong
- A. --gen-key generates a new GPG keypair; it does not operate on or encrypt an existing file.
- B. --symmetric encrypts using a shared passphrase rather than the recipient's public key, requiring separate secure passphrase distribution.
- D. --sign only creates a digital signature to prove authenticity; it does not encrypt the content.
GPG Asymmetric Encryption
GPG can encrypt data for a specific recipient using their imported public key; only the corresponding private key can decrypt the resulting ciphertext.
- gpg --encrypt --recipient <keyid/email> file
- Recipient's public key must be imported and trusted first
- Output is file.gpg by default
- Use --decrypt with the private key to read the file back
Memory trick: Public key locks the mailbox; only the private key opens it.