CAS-004 Security Engineering Practice Question
A security architect is designing a key management system for a multinational corporation that must comply with FIPS 140-3 Level 3. The system will store long-term asymmetric private keys used for digital signatures. The architect must ensure that the private keys are protected against physical extraction and that cryptographic operations are performed within a tamper-responsive environment. Which of the following is the MOST appropriate solution?
⚠ Common exam trap
The trap here is assuming that any hardware-based key storage, such as a TPM or a Level 2 HSM, automatically satisfies Level 3 requirements, when in fact Level 3 mandates tamper-responsive mechanisms and validated hardware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Hardware Security Module (HSM) that is FIPS 140-3 Level 3 validated for key storage and cryptographic operations.
FIPS 140-3 Level 3 requires tamper-responsive physical security and identity-based authentication. An HSM validated to this level provides a hardened environment that detects and responds to tampering, such as by zeroizing keys. It also performs cryptographic operations internally, preventing key exposure. Software keystores, TPMs, and Level 2 cloud KMS solutions do not meet the tamper-responsive and physical extraction resistance requirements for Level 3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a Hardware Security Module (HSM) that is FIPS 140-3 Level 3 validated for key storage and cryptographic operations.
Why this is correct
A FIPS 140-3 Level 3 validated HSM provides tamper-responsive physical security, detects and responds to tampering by zeroizing keys, and performs cryptographic operations internally. It meets the requirements for protecting long-term private keys against extraction and ensures operations occur in a secure environment, making it the most appropriate solution.
- ✗
Implement a Trusted Platform Module (TPM) 2.0 on each server to store private keys and perform signing operations.
Why it's wrong here
A TPM 2.0 provides secure storage and can perform cryptographic operations, but it is typically not validated to FIPS 140-3 Level 3 and may not offer tamper-responsive physical protection at that level. TPMs are designed for platform integrity and key protection but may not meet the stringent requirements for a centralized, high-assurance key management system.
- ✗
Store private keys in a cloud key management service (KMS) that uses FIPS 140-2 Level 2 validated hardware.
Why it's wrong here
FIPS 140-2 Level 2 does not require tamper-responsive physical security; Level 3 does. A cloud KMS with Level 2 hardware may not provide the required tamper responsiveness and physical extraction protection. Additionally, the requirement specifies FIPS 140-3, so a Level 2 solution is insufficient regardless of the provider.
- ✗
Store private keys in a software-based keystore encrypted with a passphrase and implement strict access controls.
Why it's wrong here
Software-based keystores, even with strong encryption and access controls, do not provide the tamper-responsive physical protection required for FIPS 140-3 Level 3. They are vulnerable to memory scraping, cold boot attacks, and offline extraction if the host is compromised. Therefore, they do not meet the requirement for physical extraction resistance and tamper responsiveness.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.