CAS-004 Security Engineering Practice Question
A security architect is designing a system that requires cryptographic separation of duties for key management. The organization wants to ensure that no single administrator can both generate and use a key without oversight. Which of the following key management practices BEST achieves this requirement?
⚠ Common exam trap
The trap here is assuming that an HSM automatically enforces separation of duties; it provides secure storage but not policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing dual control with split knowledge for key generation and usage
Dual control and split knowledge are specifically designed to enforce separation of duties. Dual control requires multiple authorizations, while split knowledge ensures that components of a key are divided among individuals. This combination prevents any single administrator from unilaterally generating and using a key, which is essential for high-assurance key management and compliance with standards like FIPS 140-2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a hardware security module (HSM) to store all keys
Why it's wrong here
An HSM provides secure key storage and cryptographic operations, but it does not inherently enforce separation of duties. A single administrator with access to the HSM could potentially generate and use keys. Without additional controls like dual control, the HSM alone does not prevent a single person from performing both actions, thus failing the requirement.
- ✗
Rotating keys automatically every 24 hours
Why it's wrong here
Key rotation limits the exposure window if a key is compromised, but it does not prevent a single administrator from generating and using a key within the rotation period. It is a best practice for key lifecycle management, but it does not address the separation of duties requirement, as one person could still perform both actions before rotation.
- ✗
Encrypting all keys with a master key stored in a software vault
Why it's wrong here
Encrypting keys with a master key protects data at rest but does not enforce separation of duties. If one administrator has access to the master key and the encrypted keys, they can decrypt and use them. This approach centralizes control rather than distributing it, so it does not meet the requirement for cryptographic separation of duties.
- ✓
Implementing dual control with split knowledge for key generation and usage
Why this is correct
Dual control requires two or more individuals to authorize an action, and split knowledge ensures that no single person possesses the entire key or the means to use it. Together, they enforce separation of duties, preventing a lone administrator from generating and using a key without oversight. This is a fundamental principle in high-security key management, such as in FIPS 140-2 Level 3 or higher validated modules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.