nerdexam
CompTIA

CAS-002 · Question #759

A company is facing penalties for failing to effectively comply with e-discovery requests. Which of the following could reduce the overall risk to the company from this issue?

The correct answer is D. Allow encryption only by tools that use public keys from the existing escrowed corporate PKI. E-discovery compliance requires that encrypted corporate data can always be decrypted and produced on demand; escrowed PKI guarantees centralized key recovery regardless of employee status.

Enterprise Security

Question

A company is facing penalties for failing to effectively comply with e-discovery requests. Which of the following could reduce the overall risk to the company from this issue?

Options

  • AEstablish a policy that only allows file system encryption and disallows the use of individual file
  • BRequire each user to log passwords used for file encryption to a decentralized repository.
  • CPermit users to only encrypt individual files using their domain password and archive all old user
  • DAllow encryption only by tools that use public keys from the existing escrowed corporate PKI.

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    22% (7)
  • C
    6% (2)
  • D
    56% (18)

Why each option

E-discovery compliance requires that encrypted corporate data can always be decrypted and produced on demand; escrowed PKI guarantees centralized key recovery regardless of employee status.

AEstablish a policy that only allows file system encryption and disallows the use of individual file

File system encryption without key escrow still leaves the organization unable to recover data if the encrypting user's credentials are unavailable, which does not mitigate e-discovery failure.

BRequire each user to log passwords used for file encryption to a decentralized repository.

A decentralized password repository introduces additional security vulnerabilities and does not provide the reliable, auditable key recovery that e-discovery compliance demands.

CPermit users to only encrypt individual files using their domain password and archive all old user

Archiving old domain passwords is an ad-hoc approach that lacks formal escrow governance and cannot guarantee that all encrypted files remain recoverable for legal proceedings.

DAllow encryption only by tools that use public keys from the existing escrowed corporate PKI.Correct

When encryption tools rely on public keys from a corporate PKI with escrowed private keys, the organization retains the ability to decrypt any protected file at any time through the key escrow mechanism. This directly addresses e-discovery risk because legal holds can always be fulfilled without depending on individual users, and the process is auditable and centrally governed.

Concept tested: PKI key escrow for legal e-discovery compliance

Source: https://csrc.nist.gov/glossary/term/key_escrow

Topics

#e-discovery#PKI#encryption key escrow#legal compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice