Courseiva
Security Engineering →hardMultiple Choice

CAS-004 Security Engineering Practice Question

A security architect is designing a key management system for a multinational corporation that must comply with FIPS 140-3 Level 3. The system will store long-term asymmetric private keys used for digital signatures. The architect must ensure that the private keys are protected against physical extraction and that cryptographic operations are performed within a tamper-responsive environment. Which of the following is the MOST appropriate solution?

⚠ Common exam trap

The trap here is assuming that any hardware-based key storage, such as a TPM or a Level 2 HSM, automatically satisfies Level 3 requirements, when in fact Level 3 mandates tamper-responsive mechanisms and validated hardware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Hardware Security Module (HSM) that is FIPS 140-3 Level 3 validated for key storage and cryptographic operations.

FIPS 140-3 Level 3 requires tamper-responsive physical security and identity-based authentication. An HSM validated to this level provides a hardened environment that detects and responds to tampering, such as by zeroizing keys. It also performs cryptographic operations internally, preventing key exposure. Software keystores, TPMs, and Level 2 cloud KMS solutions do not meet the tamper-responsive and physical extraction resistance requirements for Level 3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a Hardware Security Module (HSM) that is FIPS 140-3 Level 3 validated for key storage and cryptographic operations.

    Why this is correct

    A FIPS 140-3 Level 3 validated HSM provides tamper-responsive physical security, detects and responds to tampering by zeroizing keys, and performs cryptographic operations internally. It meets the requirements for protecting long-term private keys against extraction and ensures operations occur in a secure environment, making it the most appropriate solution.

  • ✗

    Implement a Trusted Platform Module (TPM) 2.0 on each server to store private keys and perform signing operations.

    Why it's wrong here

    A TPM 2.0 provides secure storage and can perform cryptographic operations, but it is typically not validated to FIPS 140-3 Level 3 and may not offer tamper-responsive physical protection at that level. TPMs are designed for platform integrity and key protection but may not meet the stringent requirements for a centralized, high-assurance key management system.

  • ✗

    Store private keys in a cloud key management service (KMS) that uses FIPS 140-2 Level 2 validated hardware.

    Why it's wrong here

    FIPS 140-2 Level 2 does not require tamper-responsive physical security; Level 3 does. A cloud KMS with Level 2 hardware may not provide the required tamper responsiveness and physical extraction protection. Additionally, the requirement specifies FIPS 140-3, so a Level 2 solution is insufficient regardless of the provider.

  • ✗

    Store private keys in a software-based keystore encrypted with a passphrase and implement strict access controls.

    Why it's wrong here

    Software-based keystores, even with strong encryption and access controls, do not provide the tamper-responsive physical protection required for FIPS 140-3 Level 3. They are vulnerable to memory scraping, cold boot attacks, and offline extraction if the host is compromised. Therefore, they do not meet the requirement for physical extraction resistance and tamper responsiveness.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.