You publish release.tar.gz and want users to be able to check its authenticity from a second, separate file, with the tarball itself left byte for byte unchanged. Which command produces that signature?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct gpg --detach-sign release.tar.gz

Correct. A detached signature is written to a separate file, release.tar.gz.sig, and contains nothing but the signature. The tarball is not rewritten, and users verify with gpg --verify release.tar.gz.sig release.tar.gz.

Not correct gpg --clearsign release.tar.gz

Wrong. --clearsign produces a new file in which the original content is embedded in readable form between armour headers. That suits plain text messages, not a binary archive.

Not correct gpg --sign release.tar.gz

Wrong. This creates release.tar.gz.gpg, a new file containing the compressed data together with the signature. Users would have to extract the payload back out of it rather than use the original archive.

Not correct gpg --encrypt --sign release.tar.gz

Wrong. That signs and also encrypts to a recipient, so only the holder of the matching private key could read the result. A public release must stay readable by everyone.

Why

The three signing modes differ only in what they do with the data: --sign packages the data and the signature into one file, --clearsign leaves the data readable inside that one file, and --detach-sign, short form -b, keeps the signature in a file of its own. Only the detached form leaves the original untouched, which is why distributions ship a .sig or .asc alongside each tarball. Verification of any of them needs the signer's public key already imported and validated in the checker's keyring.

Where this comes from

Cited
manual page gpg(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500