Courseiva
Security EngineeringmediumMultiple SelectObjective-mapped

CAS-004 Security Engineering Practice Question

A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remote attestation to verify boot measurements

Measured boot stores measurements of boot components in PCRs, and attestation allows a remote verifier to check these measurements. Secure boot verifies signatures of bootloaders, but TPM stores measurements; secure boot is a UEFI feature, though TPM can participate. Sealed storage is for data protection, not boot integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remote attestation to verify boot measurements

    Why this is correct

    TPM can sign PCR values to prove boot integrity to a remote party.

  • Platform Configuration Registers (PCRs) for storing measurements

    Why this is correct

    PCRs store hash measurements of boot components to detect tampering.

  • UEFI secure boot enforcement

    Why it's wrong here

    Secure boot is a UEFI feature, not a TPM capability, though TPM can be used with it.

  • Sealed storage to protect encryption keys

    Why it's wrong here

    Sealed storage protects data but is not directly about boot integrity.

  • Generation of RSA keys for code signing

    Why it's wrong here

    TPM can generate keys, but this is not specific to boot integrity.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.