CAS-004 Security Engineering Practice Question
A security engineer is configuring an internal certificate authority that must issue end-entity certificates to servers on a private network. Corporate policy requires that the CA's private key never reside on a network-connected host, and that certificate issuance be a deliberate, low-volume operation. Which of the following should the engineer implement to BEST meet these requirements?
⚠ Common exam trap
The trap here is assuming that placing the CA key in a hardware security module satisfies an offline-key requirement, when an online issuing CA still exposes the signing service over the network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an offline root CA that signs an online issuing subordinate CA, which in turn issues end-entity certificates.
Keeping the root CA offline and delegating routine issuance to an online subordinate CA separates the trust anchor from day-to-day operations. The root key is only used to sign the subordinate CA certificate, so it can stay on an isolated host, while the subordinate handles end-entity certificates. This limits exposure and matches the policy of deliberate, low-volume root signing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a cross-certified bridge CA that exchanges certificates with external partners using automated enrollment.
Why it's wrong here
A bridge CA is intended to federate trust between separate PKI domains, not to protect an internal trust anchor. Cross-certification expands the trust path to external entities and typically relies on online services, which conflicts with the isolation requirement. It also introduces third-party issuance that the organization cannot control, so it does not meet the stated policy.
- ✓
Configure an offline root CA that signs an online issuing subordinate CA, which in turn issues end-entity certificates.
Why this is correct
An offline root CA keeps the trust anchor's private key on an isolated system that is powered on only to sign the subordinate CA certificate. The online issuing subordinate CA handles routine end-entity issuance, so compromise of the issuing CA does not expose the root key, and the root cannot be used remotely. This directly satisfies both the isolation and low-volume issuance requirements.
- ✗
Issue self-signed certificates directly to each server and distribute them to clients through a configuration management tool.
Why it's wrong here
Self-signed certificates bypass the CA entirely, so there is no managed trust anchor, no revocation path, and no consistent policy enforcement. Distributing them via configuration management does not provide the controlled issuance the policy demands. This also fails the requirement for a CA whose private key is protected offline, since every server holds its own self-issued key.
- ✗
Deploy a single online root CA that issues all end-entity certificates and keeps its key in a network HSM.
Why it's wrong here
A network-attached HSM protects key material but the root CA remains online and reachable, so its signing service is exposed to remote abuse. Policy requires the CA private key to never reside on a network-connected host, which this design violates. It also concentrates all issuance under the trust anchor, so any compromise of that host breaks the entire hierarchy.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.