Courseiva
hardMultiple Select

CAS-004 Practice Question: Is designing a secure enclave for processing…

A security engineer is designing a secure enclave for processing sensitive personally identifiable information (PII). The enclave must protect data at rest and in use, and must support attestation to verify its integrity. Which THREE technologies should the engineer incorporate? (Choose three.)

⚠ Common exam trap

CompTIA often tests the distinction between hardware roots of trust (TPM, HSM) and actual secure enclave technologies (SGX, SEV, TrustZone), so candidates mistakenly choose TPM or HSM because they associate them with 'trust' and 'security' without understanding that enclaves require isolated memory regions for processing data in use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AMD Secure Encrypted Virtualization (SEV)

AMD Secure Encrypted Virtualization (SEV) (B) is correct because it encrypts each VM's memory with a per-VM AES key managed by the AMD Secure Processor, protecting data in use and supporting remote attestation of the VM's launch integrity. ARM TrustZone (C) is correct because it partitions the SoC into a secure world and normal world, isolating sensitive PII processing and enabling attestation of trusted applications within the secure enclave. Intel Software Guard Extensions (SGX) (D) is correct because it creates hardware-isolated enclaves (secure enclaves) whose memory is encrypted and inaccessible to the OS/hypervisor, and it provides remote attestation via quoting enclaves to verify enclave integrity. TPM (A) is not the right fit because it primarily provides sealed storage, measured boot, and platform attestation for data at rest, but it does not create an execution enclave that protects data in use. HSM (E) is not the right fit because it safeguards cryptographic keys and performs crypto operations, but it does not provide a general-purpose trusted execution environment for processing PII in use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trusted Platform Module (TPM)

    Why it's wrong here

    A TPM provides platform boot integrity and sealed key storage, but it does not create the isolated execution environment that protects PII while processing, nor produce enclave attestation evidence. It is tempting because TPMs genuinely underpin measured boot and attestation on endpoints, which would fit a host-integrity requirement rather than a runtime enclave.

  • ✓

    AMD Secure Encrypted Virtualization (SEV)

    Why this is correct

    Encrypts memory for VMs, supports attestation.

  • ✓

    ARM TrustZone

    Why this is correct

    ARM TrustZone partitions the processor into secure and normal worlds, isolating sensitive code and data in a hardware-backed trusted execution environment. This protects PII in use and supports attestation of the secure world, meeting the enclave requirement for in-use protection and integrity verification.

  • ✓

    Intel Software Guard Extensions (SGX)

    Why this is correct

    Intel SGX creates hardware-isolated enclaves within application address space, encrypting memory contents so even the OS or hypervisor cannot read them. It generates attestation quotes proving enclave integrity, directly satisfying the requirement to protect PII in use and support attestation.

  • ✗

    Hardware Security Module (HSM)

    Why it's wrong here

    An HSM safeguards cryptographic keys and performs key operations, but it does not isolate running code or generate the enclave measurement that attestation verifies. It is tempting because HSMs are genuine hardware-backed protection for keys at rest, and would be correct where the requirement is key custody and cryptographic operations rather than in-use memory protection.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.