Refer to the exhibit. A user named Alice has encrypted files using EFS. What is a potential risk associated with the current configuration?
A self-signed EFS certificate has no trusted CA or key recovery agent backing it, so if the certificate and private key are lost the encrypted files become permanently unrecoverable. Enterprise PKI-issued certificates support recovery and escrow, which self-signed ones lack.
Why this answer
The correct answer is A: the user's certificate is self-signed, which may not be recoverable if lost. In EFS, file encryption keys are protected by the user's EFS certificate and private key; if that certificate is self-signed and not backed up or escrowed (for example, via a recovery agent or CA-issued certificate), losing the private key makes the encrypted files permanently inaccessible. Option B is wrong because AES-256 is a strong, recommended EFS algorithm, not weak.
Option C is wrong because a 256-bit key is more than sufficient for EFS. Option D is wrong because EFS protection travels with the file when it is moved within the same NTFS environment, so it is not limited to the local drive.