Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect at a defense contractor must protect Controlled Unclassified Information (CUI) that flows between an on-premises data center and a government cloud enclave. The requirement states that data must remain confidential even if a cloud provider's hypervisor is compromised, and the provider must not be able to access plaintext at any layer. The architect needs a control that cryptographically isolates tenant workloads from the provider and from other tenants. Which of the following BEST satisfies this requirement?

⚠ Common exam trap

The trap here is assuming that encrypting data at rest and in transit is sufficient to keep a cloud provider from accessing plaintext, when the provider can still read decrypted data in guest memory unless confidential computing is used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement confidential computing using hardware-based trusted execution environments (TEEs) such as AMD SEV-SNP or Intel TDX.

Confidential computing with hardware TEEs encrypts guest memory using CPU-managed keys, so the hypervisor and provider administrators cannot read plaintext even during processing. The other controls protect keys, data in transit, or data at rest, but none prevent plaintext exposure in memory when the hypervisor is compromised, which is the specific threat in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypt all CUI at rest with customer-managed keys stored in a separate key management service outside the provider's control.

    Why it's wrong here

    Customer-managed keys protect data at rest and limit provider access to stored volumes, but the data must be decrypted into memory for processing, where a compromised hypervisor can read it. This control addresses storage confidentiality only and does not prevent the provider from accessing plaintext during computation.

  • ✓

    Implement confidential computing using hardware-based trusted execution environments (TEEs) such as AMD SEV-SNP or Intel TDX.

    Why this is correct

    Confidential computing encrypts guest memory with keys managed by the CPU, so even a compromised hypervisor or a malicious provider administrator sees only ciphertext. TEEs provide cryptographic isolation of tenant workloads from the provider and other tenants, directly meeting the requirement that plaintext never be exposed to the cloud provider at any layer.

  • ✗

    Deploy hardware security modules (HSMs) in the cloud provider's data center to store tenant encryption keys.

    Why it's wrong here

    HSMs protect key material and perform cryptographic operations, but if the hypervisor is compromised the attacker can still access plaintext in guest memory or intercept data before it reaches the HSM. HSMs address key custody, not runtime memory isolation from the provider, so they do not satisfy the requirement that the provider cannot access plaintext at any layer.

  • ✗

    Require TLS 1.3 with mutual authentication for all data in transit between the data center and the cloud enclave.

    Why it's wrong here

    Mutual TLS 1.3 secures data in transit and authenticates endpoints, but once data is decrypted inside the guest VM the provider's hypervisor can read it. Transit encryption does not protect data at rest or in use within the cloud enclave, so it fails the requirement that the provider cannot access plaintext at any layer.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.