SY0-301 · Question #417
After encrypting all laptop hard drives, an executive officer's laptop has trouble booting to the operating system. Now that it is successfully encrypted the helpdesk cannot retrieve the data. Which…
The correct answer is A. Recovery agent. A Recovery Agent (A) is a designated account - typically an IT administrator or a dedicated recovery account - that is pre-configured with the authority to decrypt data encrypted by any user in the organization. Technologies like EFS (Encrypting File System) and BitLocker…
Question
After encrypting all laptop hard drives, an executive officer's laptop has trouble booting to the operating system. Now that it is successfully encrypted the helpdesk cannot retrieve the data. Which of the following can be used to decrypt the information for retrieval?
Options
- ARecovery agent
- BPrivate key
- CTrust models
- DPublic key
How the community answered
(20 responses)- A90% (18)
- B5% (1)
- C5% (1)
Explanation
A Recovery Agent (A) is a designated account - typically an IT administrator or a dedicated recovery account - that is pre-configured with the authority to decrypt data encrypted by any user in the organization. Technologies like EFS (Encrypting File System) and BitLocker support recovery agents specifically for this scenario: when a user's credentials are lost or a device fails to boot, the recovery agent can decrypt the data without the original user's key. The public/private key pair belongs to the user and is unavailable if the device won't boot. Trust models are a PKI concept, not a data recovery mechanism.
Topics
Community Discussion
No community discussion yet for this question.