CAS-004 Security Engineering Practice Question
A security engineer is implementing a secure enclave using Intel SGX for a sensitive application. The engineer must ensure that the enclave's memory is protected from a compromised operating system. Which of the following BEST describes how SGX achieves this protection?
⚠ Common exam trap
The trap here is assuming that SGX relies on hypervisor isolation or simple access controls, when in fact it uses hardware memory encryption and integrity protection to defend against privileged attackers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The enclave's memory is encrypted by the CPU's memory encryption engine (MEE) and integrity-protected, so the OS cannot read or tamper with it.
Intel SGX protects enclave memory using the CPU's memory encryption engine, which encrypts data leaving the CPU and verifies integrity on return. This prevents a compromised OS from reading or altering enclave memory. Other options incorrectly describe SGX as using VMs, ACLs, or separate secure elements, which are not how SGX provides isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The enclave runs in a separate virtual machine that is isolated by the hypervisor, preventing the OS from accessing its memory.
Why it's wrong here
SGX does not use a separate VM; it creates enclaves within the same process address space. Isolation is enforced by the CPU, not a hypervisor. A hypervisor-based approach would not protect against a compromised hypervisor, which SGX is designed to defend against. This option mischaracterizes the SGX architecture.
- ✗
The enclave's memory is protected by a hardware-based access control list (ACL) that the OS cannot modify.
Why it's wrong here
While SGX uses hardware-enforced access controls, the primary protection for memory confidentiality and integrity is encryption and integrity verification by the MEE, not an ACL. An ACL alone would not prevent a privileged attacker from reading memory contents. The MEE is the key mechanism that ensures data is unreadable and tamper-evident.
- ✓
The enclave's memory is encrypted by the CPU's memory encryption engine (MEE) and integrity-protected, so the OS cannot read or tamper with it.
Why this is correct
Intel SGX uses the CPU's memory encryption engine to encrypt enclave pages when they are written to DRAM and verify their integrity when read back. This ensures that even a privileged attacker like the OS or hypervisor cannot read or modify enclave memory. The encryption keys are managed by the CPU and never exposed to software.
- ✗
The enclave's code and data are stored in a dedicated secure element (SE) that is physically separate from the main CPU.
Why it's wrong here
SGX enclaves reside in the main CPU's protected memory, not in a separate secure element. A dedicated secure element like a TPM or smart card has limited storage and processing, and is not used for general-purpose enclave execution. This option confuses SGX with other secure hardware technologies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.