Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?

⚠ Common exam trap

The trap here is conflating 'cloud KMS' with 'HSM' — candidates assume any managed key service is automatically FIPS 140-2 Level 3, when only HSM-backed offerings with dedicated hardware meet the tamper-resistance requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hardware security module

A Hardware Security Module (HSM) is a dedicated physical appliance that generates, stores, and protects cryptographic keys inside a tamper-resistant boundary. FIPS 140-2 Level 3 requires physical tamper-resistance, identity-based authentication, and key zeroization on intrusion — capabilities that only validated hardware appliances like HSMs deliver. HSMs are the standard for signing high-value financial transactions because private keys never leave the cryptographic boundary in plaintext.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Software-based key management system

    Why it's wrong here

    Software-based key management stores keys in files or a database protected only by the host OS, providing no tamper-resistant hardware and typically no FIPS 140-2 Level 3 validation. It is tempting because it is cheap and portable, and would suffice where only logical key separation, not hardware assurance, is required.

  • ✓

    Hardware security module

    Why this is correct

    A hardware security module provides tamper-resistant, FIPS 140-2 Level 3 validated hardware that generates and stores cryptographic keys internally, preventing extraction. This satisfies the requirement to protect signing keys for financial transactions with physical tamper resistance.

  • ✗

    Cloud KMS

    Why it's wrong here

    Cloud KMS commonly offers FIPS 140-2 Level 2 or Level 3 validated HSMs, but the service abstracts the hardware, so the customer cannot demonstrate tamper-resistant hardware control for signing keys. It is tempting because cloud KMS is the default managed key service for envelope encryption at scale.

  • ✗

    TPM

    Why it's wrong here

    A TPM is a motherboard-bound chip providing measured boot and platform sealing, not a general-purpose key store for signing financial transactions; it cannot be shared across servers or meet the Level 3 key-custody requirement. It is tempting because TPMs do provide tamper-resistant hardware key storage, which suits device identity and BitLocker.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.