CAS-004 Security Engineering Practice Question
A security engineer is implementing a solution to protect sensitive data stored in a database. The requirement is to ensure that even if the database files are stolen, the data cannot be read without access to a hardware security module (HSM). Which of the following should the engineer implement?
⚠ Common exam trap
The trap here is assuming that any encryption at rest is sufficient, without considering where the keys are stored and whether they are hardware-protected.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transparent Data Encryption (TDE) with keys stored in an HSM
Transparent Data Encryption with keys stored in an HSM ensures that the encryption keys are protected by hardware and never exposed in software or configuration files. This means that even if the database files are stolen, decryption is impossible without the HSM. The other options either store keys insecurely or do not provide hardware-based key protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application-level encryption with keys derived from a user password
Why it's wrong here
Application-level encryption with password-derived keys means the security depends on password strength and management. It does not involve an HSM, and if the password is weak or compromised, the data can be decrypted. This does not meet the requirement for hardware-based key protection that prevents decryption without the HSM.
- ✗
Column-level encryption with keys stored in a configuration file
Why it's wrong here
Column-level encryption encrypts specific columns, but storing keys in a configuration file means they are accessible if the file system is compromised. This does not meet the requirement that data cannot be read without the HSM, as the keys are not hardware-protected and could be stolen along with the database files.
- ✓
Transparent Data Encryption (TDE) with keys stored in an HSM
Why this is correct
TDE encrypts the database files at rest, and storing the encryption keys in an HSM ensures that the keys are protected and never exposed in software. Without the HSM, the stolen files cannot be decrypted, meeting the requirement. This approach provides strong protection for data at rest with hardware-based key management.
- ✗
Disk encryption on the database server with keys stored in the operating system keyring
Why it's wrong here
Disk encryption protects the entire disk, but if the keys are stored in the OS keyring, they may be accessible to an attacker who gains access to the running system. The requirement specifically mentions protection even if database files are stolen, implying offline access, so OS keyring protection is insufficient without HSM backing.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.