nerdexam
CompTIA

SY0-301 · Question #417

After encrypting all laptop hard drives, an executive officer's laptop has trouble booting to the operating system. Now that it is successfully encrypted the helpdesk cannot retrieve the data. Which…

The correct answer is A. Recovery agent. A Recovery Agent (A) is a designated account - typically an IT administrator or a dedicated recovery account - that is pre-configured with the authority to decrypt data encrypted by any user in the organization. Technologies like EFS (Encrypting File System) and BitLocker…

Security operations

Question

After encrypting all laptop hard drives, an executive officer's laptop has trouble booting to the operating system. Now that it is successfully encrypted the helpdesk cannot retrieve the data. Which of the following can be used to decrypt the information for retrieval?

Options

  • ARecovery agent
  • BPrivate key
  • CTrust models
  • DPublic key

How the community answered

(20 responses)
  • A
    90% (18)
  • B
    5% (1)
  • C
    5% (1)

Explanation

A Recovery Agent (A) is a designated account - typically an IT administrator or a dedicated recovery account - that is pre-configured with the authority to decrypt data encrypted by any user in the organization. Technologies like EFS (Encrypting File System) and BitLocker support recovery agents specifically for this scenario: when a user's credentials are lost or a device fails to boot, the recovery agent can decrypt the data without the original user's key. The public/private key pair belongs to the user and is unavailable if the device won't boot. Trust models are a PKI concept, not a data recovery mechanism.

Topics

#recovery agent#disk encryption#key recovery#PKI

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice