CompTIA Security+ (SY0-701)General Security ConceptsHard

A government agency requires that a copy of every employee's private encryption key be securely stored with a trusted third party so that encrypted data can still be decrypted if an employee loses their key or leaves the organization unexpectedly. What is this practice called?

  1. APerfect forward secrecy
  2. BKey stretching
  3. CKey escrow
  4. DKey pinning
Show answer & explanation

Correct answer: C. Key escrow

Key escrow is the practice of storing a copy of a private key with a trusted third party to allow recovery of encrypted data when the original key is lost or unavailable.

Why the other options are wrong

  • A. Perfect forward secrecy ensures session keys aren't derivable from long-term keys, the opposite goal of escrow.
  • B. Key stretching strengthens weak keys/passwords through repeated hashing, unrelated to key storage for recovery.
  • D. Key pinning associates a specific certificate/key with a host to prevent MITM attacks, not for recovery.

Key Escrow

The practice of storing a copy of a cryptographic private key with a trusted third party for recovery in case the original key is lost, damaged, or unavailable.

  • Enables data recovery for lost/inaccessible keys
  • Introduces a single point of trust/risk with the escrow agent
  • Often required in regulated or government environments

Memory trick: Escrow keeps a spare key locked in a trusted vault.

More General Security Concepts questions