CAS-004 Security Engineering Practice Question
A system administrator needs to securely store cryptographic keys and perform signing operations in a tamper-resistant hardware device. Which solution should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Hardware Security Module (HSM) with FIPS 140-2 Level 3 certification.
An HSM (Hardware Security Module) is designed to securely generate, store, and manage cryptographic keys in a tamper-resistant environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A Hardware Security Module (HSM) with FIPS 140-2 Level 3 certification.
Why this is correct
An HSM provides dedicated tamper-resistant hardware that generates, stores and uses cryptographic keys internally, so keys never leave the device in plaintext. FIPS 140-2 Level 3 certification confirms physical tamper resistance, satisfying the requirement for secure signing in hardware.
- ✗
A secure enclave like Intel SGX.
Why it's wrong here
Intel SGX protects code and data within per-application enclaves on the CPU, but its sealed storage is bound to that enclave and CPU, so it cannot serve as a general-purpose tamper-resistant key store for signing operations across the system. It would suit isolating a specific workload's secrets, not the stem's dedicated hardware key storage.
- ✗
A software-based key store with encrypted files.
Why it's wrong here
Encrypted files on disk provide no tamper-resistant hardware boundary; keys are decrypted into host memory during signing, exposing them to malware or memory scraping. It is tempting as a low-cost, portable key store, and would suit non-critical development secrets, but the stem explicitly demands tamper-resistant hardware performing the signing.
- ✗
A Trusted Platform Module (TPM) 2.0.
Why it's wrong here
A TPM 2.0 is a discrete tamper-resistant chip that stores keys and performs signing, but it is bound to one machine and designed for platform functions such as measured boot and disk encryption, not general-purpose signing for arbitrary applications. It would suit BitLocker or attestation, not the stem's requirement.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.