Answer:
b. For each user and computer certificate template, edit the security settings to add a recovery agent and to grant Read and Write permissions
Step-by-step explanation:
We may set a different account to be the DRA, we simply need to build a certificate for it from EFS Recovery Agent.
Which implies both the user who encrypted the file, and the DRA account, would be able to decrypt it.
It's important, as you can imagine, that the private key for the DRA is safe. It's implied that if not in service it can be safely placed offline.