CISSP-ISSAP · Question #75
Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS) to encrypt the data stored on a disk on a file-by-file basis?
The correct answer is B. Digital certificates C. Public key. EFS encrypts each file with a randomly generated symmetric File Encryption Key (FEK), which is then protected using the user's public key (asymmetric encryption) derived from their digital certificate - making B and C the two correct methods that work in tandem. Why the…
Question
Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS) to encrypt the data stored on a disk on a file-by-file basis?
Options
- ATwofish
- BDigital certificates
- CPublic key
- DRSA
How the community answered
(52 responses)- A12% (6)
- B83% (43)
- D6% (3)
Explanation
EFS encrypts each file with a randomly generated symmetric File Encryption Key (FEK), which is then protected using the user's public key (asymmetric encryption) derived from their digital certificate - making B and C the two correct methods that work in tandem.
Why the distractors are wrong:
- A. Twofish - EFS uses AES (or 3DES in older Windows versions) as its symmetric cipher, not Twofish.
- D. RSA - RSA is a specific public key algorithm, not the method category itself; the question targets the broader cryptographic method ("public key"), and EFS also supports ECC-based certificates, so RSA isn't universally correct.
Memory tip: Think of EFS as a "locked box inside a safe" - the file is locked with a symmetric key (the box), and that key is then secured inside the safe using your public key certificate. No certificate = no access, which is why losing your EFS certificate means permanently losing your data.
Topics
Community Discussion
No community discussion yet for this question.