CompTIA Security+ (SY0-701)General Security ConceptsHard
A government agency requires that a copy of every employee's private encryption key be securely stored with a trusted third party so that encrypted data can still be decrypted if an employee loses their key or leaves the organization unexpectedly. What is this practice called?
- APerfect forward secrecy
- BKey stretching
- CKey escrow
- DKey pinning
Show answer & explanationAnswer & explanation
Correct answer: C. Key escrow
Key escrow is the practice of storing a copy of a private key with a trusted third party to allow recovery of encrypted data when the original key is lost or unavailable.
Why the other options are wrong
- A. Perfect forward secrecy ensures session keys aren't derivable from long-term keys, the opposite goal of escrow.
- B. Key stretching strengthens weak keys/passwords through repeated hashing, unrelated to key storage for recovery.
- D. Key pinning associates a specific certificate/key with a host to prevent MITM attacks, not for recovery.
Key Escrow
The practice of storing a copy of a cryptographic private key with a trusted third party for recovery in case the original key is lost, damaged, or unavailable.
- Enables data recovery for lost/inaccessible keys
- Introduces a single point of trust/risk with the escrow agent
- Often required in regulated or government environments
Memory trick: Escrow keeps a spare key locked in a trusted vault.