Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?

⚠ Common exam trap

CAS-005 often tests whether candidates equate 'encrypted storage' or 'dedicated VM' with high-assurance key protection, when only an HSM provides tamper-resistant, non-exportable key custody for a root CA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Hardware Security Module (HSM) for key management

A Hardware Security Module (HSM) is a tamper-resistant physical device that generates, stores, and uses cryptographic keys within its protected boundary, never exposing the private key in plaintext. For a root CA — the trust anchor of the entire PKI — an HSM provides FIPS 140-2 Level 3 (or higher) assurance, key backup/recovery controls, and audit logging that no software-based or portable storage method can match. This is the industry-standard approach for high-assurance root CA key protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the key in an encrypted file on a secure server

    Why it's wrong here

    An encrypted file on a general-purpose server leaves the key exposed to host compromise, memory scraping, and insider copying. High-assurance roots belong in hardware security modules or offline HSMs; file encryption suits low-value keys where hardware cost is unjustified.

  • ✗

    Generate the key on a dedicated virtual machine

    Why it's wrong here

    A virtual machine is still software: the hypervisor, host OS, and snapshots can expose or duplicate the private key. Dedicated HSMs provide tamper-resistant key generation and non-exportable storage; VMs suit development or test CAs, not high-assurance roots.

  • ✓

    Use a Hardware Security Module (HSM) for key management

    Why this is correct

    An HSM is tamper-resistant hardware that generates and stores the root CA private key internally, performing signing operations without exposing the key to software or memory. This provides the physical protection and non-exportability that high-assurance root key custody demands.

  • ✗

    Keep the key on a smart card stored in a safe

    Why it's wrong here

    A smart card stores one key for one operator and cannot perform the signing throughput or multi-operator quorum a root CA requires. Smart cards suit individual user authentication certificates; root key protection demands an HSM with offline ceremony controls.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.