CAS-004 Security Architecture Practice Question
A security architect is designing a PKI for a large enterprise. Which component is used to protect private keys and perform cryptographic operations in a tamper-resistant environment?
⚠ Common exam trap
CAS-005 often tests the confusion between KMS (a key management service) and HSM (the tamper-resistant hardware), tempting candidates to pick KMS when the question emphasizes hardware protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hardware Security Module (HSM)
A Hardware Security Module (HSM) is a dedicated tamper-resistant appliance that generates, stores, and uses cryptographic keys without exposing them, performing operations like signing and encryption inside the hardware boundary. It is the standard component for protecting private keys in an enterprise PKI. HSMs provide FIPS 140-2/3 validated protection and resist physical and logical extraction attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hardware Security Module (HSM)
Why this is correct
A Hardware Security Module provides tamper-resistant hardware that generates, stores and uses private keys without exposing them to host memory, satisfying the stem's requirement for protected keys and cryptographic operations in a tamper-resistant environment. Unlike software keystores, its physical and logical controls detect intrusion and zeroise key material, defeating extraction attempts.
- ✗
Certificate Revocation List (CRL)
Why it's wrong here
A CRL is a signed list of revoked certificates that clients check during validation; it stores no private keys and performs no cryptographic operations. It is tempting because revocation is a core PKI function. A CRL would be the correct component when the requirement is publishing certificate revocation status.
- ✗
Key Management Service (KMS)
Why it's wrong here
KMS manages keys but may be software-based; HSM offers stronger physical protection.
- ✗
Certificate Authority (CA)
Why it's wrong here
A CA issues and signs certificates, but it does not itself provide the tamper-resistant hardware boundary for storing private keys and running cryptographic operations. It is tempting because CAs do hold private keys, yet the scenario requires an HSM, which the CA may rely upon.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.