Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?

⚠ Common exam trap

CAS-005 often tests the distinction between KMS (managed, software-centric key service) and HSM (dedicated tamper-resistant hardware); candidates pick KMS because it 'manages keys' but miss the tamper-resistant hardware requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hardware Security Module (HSM)

An HSM is a dedicated, tamper-resistant hardware appliance that generates, stores, and uses cryptographic keys without ever exposing them to the host OS or application memory. It provides FIPS 140-2/3 validated key protection and performs crypto operations (signing, encryption, key wrapping) inside the secure boundary. For a PKI requiring secure private key storage and tamper-resistant cryptographic operations at scale, an HSM (or cloud HSM service) is the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trusted Platform Module (TPM)

    Why it's wrong here

    TPM is a chip on the motherboard for platform integrity, not designed for enterprise PKI key management.

  • ✓

    Hardware Security Module (HSM)

    Why this is correct

    An HSM stores private keys in tamper-resistant hardware and performs cryptographic operations internally, so keys are never exposed in software memory. This satisfies both stem constraints: secure private key storage and execution within a tamper-resistant environment.

  • ✗

    Software-based keystore

    Why it's wrong here

    A software-based keystore holds private keys in ordinary files or memory, so any process with sufficient privileges can extract them and no tamper-resistant boundary exists. It suits development environments or low-assurance TLS endpoints where hardware cost is unjustified. The stem explicitly demands tamper-resistant cryptographic operations, which only a hardware security module delivers.

  • ✗

    Key Management Service (KMS) in the cloud

    Why it's wrong here

    A cloud KMS protects keys at rest and performs operations server-side, but its FIPS 140-validated boundary is a shared, multi-tenant service rather than dedicated tamper-resistant hardware you control. It suits envelope encryption of cloud data and secrets management. The scenario demands hardware security modules providing dedicated cryptographic hardware.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.