CISSP-ISSAP · Question #201
An organization wants to allow a certificate authority to gain access to the encrypted data and create digital signatures on behalf of the user. The data is encrypted using the public key from a…
The correct answer is A. Key escrow. Key escrow is correct because it is the process by which encryption keys are held by a trusted third party (like a CA), allowing that party to decrypt data and perform operations - such as creating digital signatures - on behalf of the user when authorized. This directly…
Question
An organization wants to allow a certificate authority to gain access to the encrypted data and create digital signatures on behalf of the user. The data is encrypted using the public key from a user's certificate. Which of the following processes fulfills the above requirements?
Options
- AKey escrow
- BKey storage
- CKey revocation
- DKey recovery
How the community answered
(21 responses)- A81% (17)
- B5% (1)
- C10% (2)
- D5% (1)
Explanation
Key escrow is correct because it is the process by which encryption keys are held by a trusted third party (like a CA), allowing that party to decrypt data and perform operations - such as creating digital signatures - on behalf of the user when authorized. This directly satisfies the requirement for a CA to access encrypted data and sign on the user's behalf.
Why the distractors are wrong:
- B. Key storage simply refers to securely saving keys; it implies no third-party access or delegation of signing authority.
- C. Key revocation is the process of invalidating a certificate before it expires - it's about removing trust, not granting it.
- D. Key recovery is related but narrower: it focuses on restoring lost keys to the original owner, not granting a CA ongoing delegated access and signing capability.
Memory tip: Think of escrow like a real estate escrow account - a neutral third party holds something of value (your keys) and can act on your behalf under defined conditions. If you can picture a CA holding a spare copy of your key in a secure vault, that's key escrow.
Topics
Community Discussion
No community discussion yet for this question.