CAS-004 Security Engineering Practice Question
A security engineer is configuring a hardware security module (HSM) to protect a root certificate authority's private key. The requirement is that the key must never exist in plaintext outside the HSM and must be usable by multiple authorized administrators under dual control. Which configuration BEST satisfies these requirements?
⚠ Common exam trap
The trap here is treating encryption or passphrase wrapping of an externally generated key as equivalent to never exposing plaintext, when the key was already in plaintext during generation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Generate the CA key inside the HSM as a non-extractable key and configure M of N quorum authentication for administrative operations.
The strongest protection is to have the HSM itself generate the key as non-extractable, so the private material is created and used only within the tamper-resistant boundary. Layering M of N quorum authentication ensures that no single administrator can perform sensitive CA operations, providing the dual control the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate the CA key on a hardened offline workstation, wrap it with a passphrase-derived AES key, and import the wrapped blob into the HSM.
Why it's wrong here
Generating the key outside the HSM means the plaintext key existed on the workstation's memory and disk at some point, violating the requirement that it never exist in plaintext outside the HSM. Wrapping it afterward does not erase that exposure, and the imported key may retain extractable attributes.
- ✗
Generate the CA key inside the HSM as an extractable key so that a secure backup can be made, and rely on HSM role-based access control for administrator separation.
Why it's wrong here
Marking the key extractable directly contradicts the requirement, because anyone with sufficient HSM privilege could export the plaintext key. Role-based access control governs who can invoke operations but does not implement dual control, since a single authorized administrator could still use the key alone.
- ✗
Generate the CA key inside the HSM and store a passphrase-protected copy in an encrypted configuration management database for disaster recovery.
Why it's wrong here
Storing any copy of the key outside the HSM, even encrypted, reintroduces the risk the scenario seeks to eliminate and may expose the key if the passphrase or database is compromised. The requirement is that the key never exists in plaintext outside the HSM, so external backup copies are inappropriate.
- ✓
Generate the CA key inside the HSM as a non-extractable key and configure M of N quorum authentication for administrative operations.
Why this is correct
Generating the key inside the HSM with the non-extractable attribute ensures the private key material never leaves the cryptographic boundary in plaintext. M of N quorum authentication enforces dual control by requiring multiple smartcards or credentials to authorize sensitive operations, directly meeting both requirements.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.