FC0-U71 Security Practice Question
A finance team member must share a spreadsheet containing customer account numbers with an external auditor. The team member wants to ensure that only the intended recipient can read the file contents. Which action BEST accomplishes this?
⚠ Common exam trap
The trap here is mistaking measures that discourage casual access, such as read-only flags or renamed extensions, for actual cryptographic confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt the file using the auditor's public key
Ensuring that only the intended recipient can read a file requires confidentiality that survives interception, which means cryptography tied to that recipient's identity. Encrypting with the auditor's public key ensures only the auditor's private key can decrypt the contents. Renaming, read-only attributes, and weak archive passwords all leave the data readable or easily recovered by anyone who obtains the file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Encrypt the file using the auditor's public key
Why this is correct
Encrypting with the recipient's public key means only the matching private key, held by the auditor, can decrypt the contents. Even if the message is intercepted in transit or lands in the wrong mailbox, the ciphertext is useless without that private key. This is the standard way to guarantee that a specific individual is the only party able to read a file.
- ✗
Compress the spreadsheet into a password-protected ZIP archive and email the password separately
Why it's wrong here
Separating the password into a different channel is better than sending both together, but legacy ZIP encryption is weak and many tools crack it quickly, and the password could still be intercepted. It also depends on the recipient handling two messages correctly. This is a workaround rather than a strong, purpose-built way to restrict file readability to one recipient.
- ✗
Rename the file with a .txt extension before attaching it to the email
Why it's wrong here
Changing the extension is a form of obscurity that can slip past some attachment filters, but it provides no cryptographic protection whatsoever. Anyone who receives or intercepts the message can rename the file back and open it normally. This approach hides nothing meaningful and would not stop an unintended party from reading the account numbers.
- ✗
Apply a read-only permission to the file before sending it
Why it's wrong here
Read-only is a file attribute that discourages casual editing, but it does nothing to prevent viewing or copying. The recipient's system can trivially remove the attribute, and an interceptor can read the contents immediately. This option confuses restricting modification with restricting who can read, which is the actual requirement in this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.