mediumMultiple Choice
CAS-004 Practice Question: A company has implemented a hardware security…
A company has implemented a hardware security module (HSM) to manage cryptographic keys for a payment processing system. Which of the following best describes an advantage of using an HSM over software-based key storage?
⚠ Common exam trap
CAS-005 often tests whether candidates confuse the security benefits of HSMs (tamper resistance, secure key storage) with performance or cost benefits, leading them to incorrectly select 'faster cryptographic operations' or 'lower implementation cost' as advantages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tamper-resistant key storage
An HSM is a dedicated hardware device designed to securely generate, store, and manage cryptographic keys, with physical and logical protections that make it tamper-resistant. Unlike software-based key storage, where keys reside in memory or on disk and can be extracted by malware or an attacker with system access, an HSM's keys never leave the device in plaintext and the device zeroizes keys if tampering is detected. This makes tamper-resistant key storage the primary advantage for high-assurance environments like payment processing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Easier key rotation
Why it's wrong here
An HSM's advantage is tamper-resistant hardware that prevents key extraction, whereas software storage leaves keys exposed in memory or on disk. Key rotation is a procedural capability available in both; software keystores and cloud key vaults handle rotation schedules equally well. Rotation convenience would matter when operational overhead, not key protection, drives the choice.
- ✓
Tamper-resistant key storage
Why this is correct
An HSM stores keys inside tamper-resistant hardware that detects and responds to physical intrusion, zeroising keys rather than exposing them. Software-based storage keeps keys in memory or on disk, where compromise of the host yields the key material directly.
- ✗
Faster cryptographic operations
Why it's wrong here
Speed is not the axis on which HSMs beat software keystores; throughput is typically bounded by the HSM's own cryptographic engine and interface. HSMs are tempting because they do accelerate bulk signing in high-volume PKI, but here the requirement is tamper-resistant key custody, which software storage cannot provide.
- ✗
Lower implementation cost
Why it's wrong here
HSMs are dedicated tamper-resistant appliances, so capital and operational costs exceed software keystores, which run on existing hosts. They are tempting where budget dominates and keys are low-value, but this payment scenario demands FIPS-validated key isolation and physical tamper response that software storage cannot deliver.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.