CAS-004 Security Engineering Practice Question
A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The architect plans to use full-disk encryption (FDE) with a TPM 2.0 module. Which of the following BEST describes a limitation of this approach that the architect must address?
⚠ Common exam trap
The trap here is believing that full-disk encryption continues to protect data after the operating system has booted and unlocked the volume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FDE with TPM does not protect data if the operating system is running and an attacker gains remote access.
Full-disk encryption with TPM protects data at rest when the system is off or locked. Once the OS is running, the volume is decrypted and accessible to any process with sufficient privileges, including remote attackers. This runtime exposure is the key limitation. Other options misstate TPM capabilities or conflate optional features with fundamental constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FDE with TPM does not protect data if the operating system is running and an attacker gains remote access.
Why this is correct
Full-disk encryption protects data only when the system is powered off or the volume is locked. Once the OS is running and the volume is decrypted, any process or remote attacker with sufficient privileges can read the data. The TPM unseals the key during boot, so the disk remains transparently accessible. This limitation means additional controls like file-level encryption or access controls are needed for runtime protection.
- ✗
TPM 2.0 modules are vulnerable to cold boot attacks that can extract the encryption key from RAM.
Why it's wrong here
Cold boot attacks target DRAM to recover encryption keys, but TPM 2.0 is designed to resist key extraction by storing keys in shielded memory and releasing them only to authorized code. While cold boot attacks can affect systems without TPM or with poor implementations, TPM 2.0 mitigates this by not exposing keys directly to the CPU. This option mischaracterizes the primary limitation of FDE with TPM.
- ✗
TPM 2.0 requires a PIN to be entered at every boot, which is impractical for servers.
Why it's wrong here
TPM 2.0 can operate without a PIN, using only the boot measurements to unseal the key automatically. A PIN is optional and often used for pre-boot authentication on endpoints. Servers can use TPM without PIN for unattended operation, though this reduces protection against physical attacks. The impracticality of PIN entry is not an inherent limitation of TPM 2.0 for servers.
- ✗
FDE with TPM cannot be used with self-encrypting drives (SEDs) or hardware encryption.
Why it's wrong here
FDE with TPM is often used in conjunction with SEDs, where the drive performs encryption and the TPM stores the authentication key. These technologies are complementary, not mutually exclusive. The scenario does not mention SEDs, and the statement is factually incorrect. The real limitation of FDE is its inability to protect data while the system is running and unlocked.
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.