nerdexam
(ISC)2

CISSP-ISSAP · Question #201

An organization wants to allow a certificate authority to gain access to the encrypted data and create digital signatures on behalf of the user. The data is encrypted using the public key from a…

The correct answer is A. Key escrow. Key escrow is correct because it is the process by which encryption keys are held by a trusted third party (like a CA), allowing that party to decrypt data and perform operations - such as creating digital signatures - on behalf of the user when authorized. This directly…

Identity and Access Management (IAM) Architecture

Question

An organization wants to allow a certificate authority to gain access to the encrypted data and create digital signatures on behalf of the user. The data is encrypted using the public key from a user's certificate. Which of the following processes fulfills the above requirements?

Options

  • AKey escrow
  • BKey storage
  • CKey revocation
  • DKey recovery

How the community answered

(21 responses)
  • A
    81% (17)
  • B
    5% (1)
  • C
    10% (2)
  • D
    5% (1)

Explanation

Key escrow is correct because it is the process by which encryption keys are held by a trusted third party (like a CA), allowing that party to decrypt data and perform operations - such as creating digital signatures - on behalf of the user when authorized. This directly satisfies the requirement for a CA to access encrypted data and sign on the user's behalf.

Why the distractors are wrong:

  • B. Key storage simply refers to securely saving keys; it implies no third-party access or delegation of signing authority.
  • C. Key revocation is the process of invalidating a certificate before it expires - it's about removing trust, not granting it.
  • D. Key recovery is related but narrower: it focuses on restoring lost keys to the original owner, not granting a CA ongoing delegated access and signing capability.

Memory tip: Think of escrow like a real estate escrow account - a neutral third party holds something of value (your keys) and can act on your behalf under defined conditions. If you can picture a CA holding a spare copy of your key in a secure vault, that's key escrow.

Topics

#Key Escrow#Certificate Authority#Digital Signatures#PKI

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice