CAS-004 Security Engineering Practice Question
A security architect must protect data at rest on a database server while allowing a backup application to read the raw encrypted files without ever holding the plaintext data key. The architect wants a design where a hardware security module (HSM) enforces key usage policy and keys never leave the module in plaintext. Which approach BEST satisfies these requirements?
⚠ Common exam trap
The trap here is treating any hardware-rooted key storage as equivalent, when only an HSM enforcing wrap and unwrap policy keeps the plaintext data key from ever leaving the boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use envelope encryption where the data key is wrapped by a master key resident in the HSM, and decrypt the data key only inside the HSM for authorized operations.
Envelope encryption separates the bulk data key from a master key held inside the HSM. Backup processes can handle ciphertext without ever seeing the plaintext data key, because unwrapping occurs only within the HSM under its enforced policy. This design satisfies both the confidentiality requirement and the constraint that key material never leaves the hardware module.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply full-disk encryption with a passphrase-protected key and share the passphrase with the backup operators.
Why it's wrong here
Sharing a passphrase with operators exposes the key to humans and gives no hardware-enforced usage policy. Full-disk encryption protects data only when the volume is offline; once mounted, the key is present in memory and usable by any privileged process. This approach cannot guarantee the raw encrypted files remain inaccessible without the plaintext data key.
- ✗
Encrypt the database with a key stored in a software keystore and grant the backup service read access to that keystore.
Why it's wrong here
A software keystore places the key material where the backup service and any compromised process on the host can read it, defeating the goal that keys never leave a protected boundary. It also gives the backup application effective access to the plaintext key, contradicting the requirement. This design does not enforce key usage policy in hardware, so it fails the scenario.
- ✗
Store the data key in a TPM sealed to the database server's boot measurements and let the backup service request unsealing remotely.
Why it's wrong here
A TPM seals a key to a specific platform state and normally releases it only to local code, so a remote backup service cannot obtain it without weakening the seal. Even if it could, unsealing exports the key into host memory, violating the requirement that keys never leave a hardware boundary in plaintext. This does not meet the HSM policy enforcement goal.
- ✓
Use envelope encryption where the data key is wrapped by a master key resident in the HSM, and decrypt the data key only inside the HSM for authorized operations.
Why this is correct
Envelope encryption keeps bulk data encrypted under a data key, while the HSM holds the master key that wraps it. The backup application can copy ciphertext freely, but unwrapping the data key happens only inside the HSM under its usage policy, so the plaintext key never leaves the module. This satisfies both the at-rest protection and HSM-enforced control requirements.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.