mediumMultiple Choice
CISSP Practice Question: Refer to the exhibit
Exhibit
C:\> cipher /u /n List of files encrypted with EFS: C:\Users\Alice\Documents\ProjectX.docx C:\Users\Alice\Desktop\Notes.txt C:\> cipher /c "C:\Users\Alice\Documents\ProjectX.docx" Encryption algorithm: AES Key length: 256 bits Certificate thumbprint: A1B2C3D4E5F6... Certificate issuer: CN=Alice Certificate expiration: 12/31/2025 Certificate is self-signed. C:\> whoami /user User Name: CONTOSO\Alice
Refer to the exhibit. A user named Alice has encrypted files using EFS. What is a potential risk associated with the current configuration?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's certificate is self-signed, which may not be recoverable if lost.
The correct answer is A: the user's certificate is self-signed, which may not be recoverable if lost. In EFS, file encryption keys are protected by the user's EFS certificate and private key; if that certificate is self-signed and not backed up or escrowed (for example, via a recovery agent or CA-issued certificate), losing the private key makes the encrypted files permanently inaccessible. Option B is wrong because AES-256 is a strong, recommended EFS algorithm, not weak. Option C is wrong because a 256-bit key is more than sufficient for EFS. Option D is wrong because EFS protection travels with the file when it is moved within the same NTFS environment, so it is not limited to the local drive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user's certificate is self-signed, which may not be recoverable if lost.
Why this is correct
A self-signed EFS certificate has no trusted CA or key recovery agent backing it, so if the certificate and private key are lost the encrypted files become permanently unrecoverable. Enterprise PKI-issued certificates support recovery and escrow, which self-signed ones lack.
- ✗
The encryption algorithm is weak; AES-256 is not recommended.
Why it's wrong here
AES-256 is a strong, recommended algorithm, so calling it weak is factually wrong. It is tempting because algorithm choice is a genuine EFS consideration, but the real risk lies in key management and recovery agent scope, not the cipher selected.
- ✗
The key length is insufficient; 256 bits is too short.
Why it's wrong here
AES-256 is the strongest standard symmetric key length and is not considered insufficient. The option is tempting because longer keys sound stronger, but the actual EFS risk concerns key protection and recovery agent configuration, not the 256-bit key size itself.
- ✗
The files are encrypted only on the local drive; they are not protected if moved to a network share.
Why it's wrong here
EFS encryption is preserved on NTFS volumes, but if moved to a non-NTFS share, decryption may occur.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Disaster Recovery Planning
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.