Courseiva
mediumMultiple Choice

CISSP Practice Question: Refer to the exhibit

Exhibit

C:\> cipher /u /n
 List of files encrypted with EFS:
 C:\Users\Alice\Documents\ProjectX.docx
 C:\Users\Alice\Desktop\Notes.txt

C:\> cipher /c "C:\Users\Alice\Documents\ProjectX.docx"
Encryption algorithm: AES
Key length: 256 bits
Certificate thumbprint: A1B2C3D4E5F6...
Certificate issuer: CN=Alice
Certificate expiration: 12/31/2025
Certificate is self-signed.

C:\> whoami /user
User Name: CONTOSO\Alice

Refer to the exhibit. A user named Alice has encrypted files using EFS. What is a potential risk associated with the current configuration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user's certificate is self-signed, which may not be recoverable if lost.

The correct answer is A: the user's certificate is self-signed, which may not be recoverable if lost. In EFS, file encryption keys are protected by the user's EFS certificate and private key; if that certificate is self-signed and not backed up or escrowed (for example, via a recovery agent or CA-issued certificate), losing the private key makes the encrypted files permanently inaccessible. Option B is wrong because AES-256 is a strong, recommended EFS algorithm, not weak. Option C is wrong because a 256-bit key is more than sufficient for EFS. Option D is wrong because EFS protection travels with the file when it is moved within the same NTFS environment, so it is not limited to the local drive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user's certificate is self-signed, which may not be recoverable if lost.

    Why this is correct

    A self-signed EFS certificate has no trusted CA or key recovery agent backing it, so if the certificate and private key are lost the encrypted files become permanently unrecoverable. Enterprise PKI-issued certificates support recovery and escrow, which self-signed ones lack.

  • ✗

    The encryption algorithm is weak; AES-256 is not recommended.

    Why it's wrong here

    AES-256 is a strong, recommended algorithm, so calling it weak is factually wrong. It is tempting because algorithm choice is a genuine EFS consideration, but the real risk lies in key management and recovery agent scope, not the cipher selected.

  • ✗

    The key length is insufficient; 256 bits is too short.

    Why it's wrong here

    AES-256 is the strongest standard symmetric key length and is not considered insufficient. The option is tempting because longer keys sound stronger, but the actual EFS risk concerns key protection and recovery agent configuration, not the 256-bit key size itself.

  • ✗

    The files are encrypted only on the local drive; they are not protected if moved to a network share.

    Why it's wrong here

    EFS encryption is preserved on NTFS volumes, but if moved to a non-NTFS share, decryption may occur.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.