CAS-004 Security Engineering Practice Question
A security architect must protect a hardware security module's firmware against an attacker who has physical access and can measure power consumption and electromagnetic emissions during signature operations. The architect wants a countermeasure that makes the secret key statistically uncorrelated with the observable side-channel leakage. Which approach BEST meets this goal?
⚠ Common exam trap
The trap here is assuming that protecting the key's storage or the integrity of the firmware also hides the key's runtime leakage from physical measurement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement constant-time modular exponentiation with blinding of the base and exponent
Base and exponent blinding combined with constant-time arithmetic randomize the intermediate values on which the leakage depends, so power and EM traces no longer correlate with the secret exponent. Secure boot, at-rest encryption, and rate limiting all leave the runtime arithmetic unchanged and therefore do not stop differential power analysis by an attacker with physical measurement access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement constant-time modular exponentiation with blinding of the base and exponent
Why this is correct
Constant-time execution removes data-dependent branches and memory-access timing, while base blinding randomizes the operand and exponent blinding randomizes the private exponent value used in each operation. Together they decorrelate the power and EM traces from the actual secret key, directly defeating statistical side-channel analysis even when the attacker can physically measure the device.
- ✗
Rate-limit signature operations to ten per second and log each attempt
Why it's wrong here
Rate limiting reduces the volume of traces an attacker collects, but side-channel attacks can succeed with a few thousand well-aligned traces and an attacker with physical access can simply wait or capture across sessions. Logging provides detection only after leakage has occurred, so this does not prevent the key from being recovered.
- ✗
Enable secure boot with a signed firmware image verified by an on-die ROM
Why it's wrong here
Secure boot ensures only authorized firmware runs but does nothing to hide the relationship between secret-key bits and the power or EM leakage produced during computation. An attacker with physical access can still perform differential power analysis on the legitimate signed firmware, so this control does not achieve side-channel resistance.
- ✗
Store the private key in encrypted form using an AES key derived from a PIN
Why it's wrong here
Encrypting the key at rest protects it when the device is powered off, but once the PIN is supplied and the key is loaded for signing, the plaintext key drives the arithmetic and its leakage is fully observable. This addresses key theft from storage, not the runtime side channel the attacker is exploiting.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.