CAS-004 Security Architecture Practice Question
A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?
⚠ Common exam trap
The trap here is conflating 'cloud KMS' with 'HSM' — candidates assume any managed key service is automatically FIPS 140-2 Level 3, when only HSM-backed offerings with dedicated hardware meet the tamper-resistance requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hardware security module
A Hardware Security Module (HSM) is a dedicated physical appliance that generates, stores, and protects cryptographic keys inside a tamper-resistant boundary. FIPS 140-2 Level 3 requires physical tamper-resistance, identity-based authentication, and key zeroization on intrusion — capabilities that only validated hardware appliances like HSMs deliver. HSMs are the standard for signing high-value financial transactions because private keys never leave the cryptographic boundary in plaintext.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software-based key management system
Why it's wrong here
Software-based key management stores keys in files or a database protected only by the host OS, providing no tamper-resistant hardware and typically no FIPS 140-2 Level 3 validation. It is tempting because it is cheap and portable, and would suffice where only logical key separation, not hardware assurance, is required.
- ✓
Hardware security module
Why this is correct
A hardware security module provides tamper-resistant, FIPS 140-2 Level 3 validated hardware that generates and stores cryptographic keys internally, preventing extraction. This satisfies the requirement to protect signing keys for financial transactions with physical tamper resistance.
- ✗
Cloud KMS
Why it's wrong here
Cloud KMS commonly offers FIPS 140-2 Level 2 or Level 3 validated HSMs, but the service abstracts the hardware, so the customer cannot demonstrate tamper-resistant hardware control for signing keys. It is tempting because cloud KMS is the default managed key service for envelope encryption at scale.
- ✗
TPM
Why it's wrong here
A TPM is a motherboard-bound chip providing measured boot and platform sealing, not a general-purpose key store for signing financial transactions; it cannot be shared across servers or meet the Level 3 key-custody requirement. It is tempting because TPMs do provide tamper-resistant hardware key storage, which suits device identity and BitLocker.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.