The correct answer is A practice where a trusted third party holds copies of encryption keys. Key escrow is a practice where a trusted third party (the escrow agent) holds copies of encryption keys. The purpose is to ensure that authorized parties, such as law enforcement with proper legal authorization or organizations needing business continuity, can access encrypted data if the primary keys are unavailable.
A technique to encrypt the same data with multiple keys is incorrect because this describes multi-key encryption, not key escrow.
A method to derive multiple keys from a master key is incorrect because this describes key derivation functions, not key escrow.
A procedure to securely transfer keys between systems is incorrect because this relates to key distribution, not escrow.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the benefits of key escrow in cryptographic systems?
Open an interactive chat with Bash
Who typically serves as the trusted third party in key escrow?
Open an interactive chat with Bash
What are the potential risks associated with key escrow?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Information Technology Package Join Premium for Full Access