CAS-004 Security Architecture Practice Question
A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?
⚠ Common exam trap
CAS-005 often tests the distinction between KMS (managed, software-centric key service) and HSM (dedicated tamper-resistant hardware); candidates pick KMS because it 'manages keys' but miss the tamper-resistant hardware requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hardware Security Module (HSM)
An HSM is a dedicated, tamper-resistant hardware appliance that generates, stores, and uses cryptographic keys without ever exposing them to the host OS or application memory. It provides FIPS 140-2/3 validated key protection and performs crypto operations (signing, encryption, key wrapping) inside the secure boundary. For a PKI requiring secure private key storage and tamper-resistant cryptographic operations at scale, an HSM (or cloud HSM service) is the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trusted Platform Module (TPM)
Why it's wrong here
TPM is a chip on the motherboard for platform integrity, not designed for enterprise PKI key management.
- ✓
Hardware Security Module (HSM)
Why this is correct
An HSM stores private keys in tamper-resistant hardware and performs cryptographic operations internally, so keys are never exposed in software memory. This satisfies both stem constraints: secure private key storage and execution within a tamper-resistant environment.
- ✗
Software-based keystore
Why it's wrong here
A software-based keystore holds private keys in ordinary files or memory, so any process with sufficient privileges can extract them and no tamper-resistant boundary exists. It suits development environments or low-assurance TLS endpoints where hardware cost is unjustified. The stem explicitly demands tamper-resistant cryptographic operations, which only a hardware security module delivers.
- ✗
Key Management Service (KMS) in the cloud
Why it's wrong here
A cloud KMS protects keys at rest and performs operations server-side, but its FIPS 140-validated boundary is a shared, multi-tenant service rather than dedicated tamper-resistant hardware you control. It suits envelope encryption of cloud data and secrets management. The scenario demands hardware security modules providing dedicated cryptographic hardware.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.