CAS-004 Security Engineering Practice Question
A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remote attestation to verify boot measurements
TPM 2.0 can produce a signed quote of PCR values that a remote verifier uses to attest that the boot chain matches expected measurements, directly ensuring boot-process integrity. Option B (Platform Configuration Registers (PCRs) for storing measurements) is correct because TPM 2.0 PCRs hold the cumulative hashes of boot components (firmware, bootloader, OS) that form the basis of measured boot and are the values attested in option A. Option C is not a TPM capability; UEFI Secure Boot enforcement is performed by UEFI firmware using signature databases (db, dbx, KEK, PK), though the TPM may record its state. Option D, sealed storage, protects encryption keys by binding them to PCR values, but it is a data-protection feature rather than a direct boot-integrity capability. Option E, RSA key generation for code signing, is a general cryptographic function and not specifically tied to ensuring boot-process integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Remote attestation to verify boot measurements
Why this is correct
Remote attestation lets the TPM sign a quote over selected PCR values, allowing a remote verifier to confirm the boot chain matched expected measurements. This satisfies the integrity-verification requirement by detecting tampering with firmware or boot components before trust is granted.
- ✓
Platform Configuration Registers (PCRs) for storing measurements
Why this is correct
Platform Configuration Registers hold cumulative cryptographic hashes of boot components, extended sequentially as each stage loads. Measured boot records these values so later attestation can prove the boot sequence was unmodified, directly supporting the integrity requirement in the stem.
- ✗
UEFI secure boot enforcement
Why it's wrong here
UEFI secure boot enforcement is performed by the firmware using signature databases and platform keys; the TPM stores measurements and seals secrets but does not enforce signature validation of boot loaders. It is tempting because the two are deployed together, yet enforcement is a firmware function, not a TPM capability.
- ✗
Sealed storage to protect encryption keys
Why it's wrong here
Sealed storage protects encryption keys by releasing them only when specified PCR values match, which supports disk encryption rather than boot-process integrity measurement. It is tempting because sealing depends on PCR measurements, but it protects key confidentiality instead of verifying that boot components are unmodified.
- ✗
Generation of RSA keys for code signing
Why it's wrong here
RSA key generation is a general-purpose cryptographic capability of TPM 2.0, used for identity, attestation and signing, but it does not itself measure or verify boot components. It is tempting because code signing keys do support secure boot, yet the signing happens outside the TPM's boot-integrity measurements.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.