CAS-004 Security Engineering Practice Question
A security engineer is implementing a secure boot process for an embedded device. The engineer needs to ensure that only trusted firmware is executed and that the integrity of the boot chain is maintained. Which TWO of the following are essential components of a secure boot implementation? (Choose two.)
⚠ Common exam trap
The trap here is equating measured boot with secure boot; measured boot records but does not enforce, while secure boot enforces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Digital signature verification of each boot stage
Secure boot requires an immutable root of trust to anchor trust and digital signature verification at each stage to ensure only trusted code executes. Encryption, secure enclaves, and TPMs can complement security but are not essential for the fundamental secure boot process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full disk encryption of the boot partition
Why it's wrong here
Full disk encryption protects data at rest but does not ensure the integrity or authenticity of the boot code. An attacker could still modify the bootloader or firmware and the system would execute it, even if the disk is encrypted. Encryption alone does not provide secure boot; it addresses confidentiality, not integrity.
- ✗
Trusted Platform Module (TPM) for measured boot
Why it's wrong here
A TPM can be used for measured boot, which records measurements but does not enforce secure boot. Measured boot provides attestation, not prevention. Secure boot requires enforcement of signatures before execution. A TPM is optional and not essential for the core secure boot functionality, which is to prevent untrusted code from running.
- ✓
Digital signature verification of each boot stage
Why this is correct
Each boot stage must be digitally signed by a trusted authority, and the signature must be verified before execution. This ensures that only authorized code runs. Without verification, an attacker could replace a boot stage with malicious code. The verification uses the public key from the root of trust or a chain of trust.
- ✗
Secure enclave for key storage
Why it's wrong here
A secure enclave can protect keys but is not an essential component of secure boot. Secure boot primarily relies on signature verification and a root of trust. While a secure enclave can enhance security, it is not required for the boot chain integrity. Many secure boot implementations work without a dedicated secure enclave.
- ✓
Root of trust in immutable hardware
Why this is correct
A root of trust in immutable hardware, such as a ROM or one-time programmable memory, is the foundation of secure boot. It contains the first piece of code executed and the public key used to verify the next stage. Without an immutable root of trust, an attacker could modify the initial boot code and bypass all subsequent verification.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.