Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A security team is deploying a hardware security module (HSM) to protect the root of trust for a code-signing pipeline. The team must ensure that signing keys cannot be extracted and that all signing operations are attributable to an authorized operator. Which TWO controls BEST meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is accepting FIPS validation as if it automatically guarantees non-extractable keys and operator attribution, when those depend on configuration and identity management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the HSM to mark signing keys as non-extractable and perform all cryptographic operations inside the module

Marking keys non-extractable and performing operations inside the module protects the signing key from extraction, while per-operator authentication with operation logging provides attribution. Backup exports and shared service accounts undermine both goals, and FIPS validation is a module-level compliance attribute rather than an operational control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store an encrypted backup of the HSM's key material on a network share protected by share-level permissions

    Why it's wrong here

    Exporting key material, even encrypted, defeats the non-extractable guarantee and creates an offline attack target. Share-level permissions are weak protection for a root-of-trust secret and do not provide operator attribution for signing. This control actively undermines the requirement that keys cannot be extracted.

  • ✗

    Enable FIPS 140-3 validated mode on the HSM and publish the validation certificate internally

    Why it's wrong here

    FIPS validation confirms the module meets a security standard, but it does not by itself make keys non-extractable in a given configuration or attribute signatures to operators. Validation is a compliance property of the module, not a control that enforces the two operational requirements in this scenario. Publishing the certificate changes nothing technically.

  • ✓

    Configure the HSM to mark signing keys as non-extractable and perform all cryptographic operations inside the module

    Why this is correct

    Non-extractable keys that never leave the HSM boundary ensure the private key cannot be copied or exfiltrated, satisfying the key-protection requirement. Because signing happens inside the module, the plaintext key is never exposed to the host OS or application memory, which is exactly the property needed for a code-signing root of trust.

  • ✓

    Enable per-operator authentication to the HSM and log each signing operation with the operator identity and key reference

    Why this is correct

    Requiring individual operator authentication and recording the identity and key used for every signature creates attribution and non-repudiation. This satisfies the requirement that signing operations be traceable to an authorized operator, and the logs provide evidence if a key misuse or policy violation is investigated later.

  • ✗

    Configure the HSM to allow a shared service account to perform signing so that automation is not interrupted

    Why it's wrong here

    A shared service account removes individual attribution, so signatures cannot be tied to a specific authorized operator. It directly conflicts with the requirement for attributable signing operations and also weakens accountability if the credential is abused. Shared identities are a common audit finding in key-management environments.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.