CAS-004 Security Architecture Practice Question
A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?
⚠ Common exam trap
CAS-005 often tests whether candidates equate 'encrypted storage' or 'dedicated VM' with high-assurance key protection, when only an HSM provides tamper-resistant, non-exportable key custody for a root CA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Hardware Security Module (HSM) for key management
A Hardware Security Module (HSM) is a tamper-resistant physical device that generates, stores, and uses cryptographic keys within its protected boundary, never exposing the private key in plaintext. For a root CA — the trust anchor of the entire PKI — an HSM provides FIPS 140-2 Level 3 (or higher) assurance, key backup/recovery controls, and audit logging that no software-based or portable storage method can match. This is the industry-standard approach for high-assurance root CA key protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the key in an encrypted file on a secure server
Why it's wrong here
An encrypted file on a general-purpose server leaves the key exposed to host compromise, memory scraping, and insider copying. High-assurance roots belong in hardware security modules or offline HSMs; file encryption suits low-value keys where hardware cost is unjustified.
- ✗
Generate the key on a dedicated virtual machine
Why it's wrong here
A virtual machine is still software: the hypervisor, host OS, and snapshots can expose or duplicate the private key. Dedicated HSMs provide tamper-resistant key generation and non-exportable storage; VMs suit development or test CAs, not high-assurance roots.
- ✓
Use a Hardware Security Module (HSM) for key management
Why this is correct
An HSM is tamper-resistant hardware that generates and stores the root CA private key internally, performing signing operations without exposing the key to software or memory. This provides the physical protection and non-exportability that high-assurance root key custody demands.
- ✗
Keep the key on a smart card stored in a safe
Why it's wrong here
A smart card stores one key for one operator and cannot perform the signing throughput or multi-operator quorum a root CA requires. Smart cards suit individual user authentication certificates; root key protection demands an HSM with offline ceremony controls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.