CAS-004 Security Engineering Practice Question
A security engineer is implementing secure boot for an embedded Linux device that uses U-Boot. The requirement is to ensure that only authenticated firmware can execute, and that the root of trust is immutable. Which of the following should the engineer implement?
⚠ Common exam trap
It's easy for candidates to confuse measured boot with verified boot; measured boot only records measurements for attestation, while verified boot actually enforces signature checks and halts on failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verified boot using a public key stored in one-time programmable (OTP) fuses to verify the bootloader signature.
To ensure only authenticated firmware executes with an immutable root of trust, the engineer should use verified boot with a public key stored in OTP fuses. The fuses cannot be changed after programming, providing immutability. The bootloader uses the public key to verify signatures on subsequent stages, creating a chain of trust. Encryption and measured boot do not enforce authentication, and symmetric keys in mutable storage are insecure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verified boot using a public key stored in one-time programmable (OTP) fuses to verify the bootloader signature.
Why this is correct
Storing the public key in OTP fuses creates an immutable root of trust that cannot be altered without physical tampering. The bootloader verifies its own signature or the next stage's signature using this key, establishing a chain of trust. This ensures that only firmware signed with the corresponding private key can execute, meeting the requirements for authentication and immutability. It is a standard approach for secure boot in embedded systems.
- ✗
Measured boot using a TPM to record hashes of each boot stage.
Why it's wrong here
Measured boot records hashes of boot components into TPM PCRs but does not enforce signature verification. It allows a remote party to attest to the boot state, but the device will still boot even if the measurements indicate tampering. Without a verification step that halts execution on failure, measured boot alone does not prevent unauthorized firmware from running. It is complementary to secure boot but not sufficient by itself.
- ✗
Encrypted boot using AES-256 to encrypt the kernel and root filesystem.
Why it's wrong here
Encrypted boot protects the confidentiality of the firmware but does not authenticate it. An attacker could still replace the encrypted image with a malicious one, and the device would decrypt and execute it without verifying the source. While encryption is useful for protecting intellectual property or secrets, it does not provide the integrity and authenticity guarantees required for secure boot.
- ✗
Secure boot using a symmetric key stored in the bootloader environment.
Why it's wrong here
Using a symmetric key stored in the bootloader environment is insecure because the environment is typically stored in mutable flash and can be modified by an attacker. A symmetric key also does not provide non-repudiation and must be shared, increasing risk. The root of trust must be immutable and based on asymmetric cryptography, so this approach fails to meet the requirements.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.