Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security architect is designing a secure boot process for a new line of embedded devices. The boot ROM loads the bootloader, which then loads the OS kernel. To ensure that only signed code is executed, which mechanism should the bootloader use to verify the kernel?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify a digital signature on the kernel using a public key stored in the boot ROM

The bootloader should verify a digital signature on the kernel image using a public key embedded in the boot ROM or bootloader. This ensures both integrity and authenticity of the kernel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Decrypt the kernel using a symmetric key stored in the boot ROM

    Why it's wrong here

    Symmetric decryption proves only that the ciphertext was produced with the shared key; it does not verify the signer's identity, and any holder of the boot ROM key can encrypt arbitrary code. It is tempting because encrypted firmware images are common, and decryption would be correct where confidentiality of the kernel image is the requirement.

  • ✓

    Verify a digital signature on the kernel using a public key stored in the boot ROM

    Why this is correct

    The boot ROM's stored public key forms an immutable root of trust, so the bootloader verifies the kernel's digital signature before transferring control. This chains trust from ROM to kernel, enforcing the requirement that only signed code executes on the embedded device.

  • ✗

    Check that the kernel file size matches the expected value

    Why it's wrong here

    A size check detects only truncation or padding, not forged content, so an attacker can substitute a malicious kernel of identical length and it passes. It is tempting because size validation is a cheap integrity sanity check, and it would be the right choice for detecting incomplete firmware downloads or storage corruption.

  • ✗

    Compare the kernel hash against a list of known good hashes stored in the bootloader

    Why it's wrong here

    A static list of known good hashes cannot authenticate new or updated kernels, and the list itself is unauthenticated, so tampering with the bootloader defeats it. It is tempting because hash comparison is a genuine integrity mechanism, and it would be correct for verifying fixed, never-updated firmware against a trusted baseline.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.