Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An organization wants to protect cryptographic keys used for TLS termination. Which hardware solution should be deployed to prevent key extraction?

⚠ Common exam trap

CAS-005 often tests the KMS vs. HSM distinction — candidates pick KMS because it 'manages keys,' missing that the question demands hardware-level prevention of key extraction, which only an HSM provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HSM

A Hardware Security Module (HSM) is a dedicated tamper-resistant hardware appliance designed to generate, store, and manage cryptographic keys, with physical and logical protections that prevent key extraction. For TLS termination, HSMs provide FIPS 140-2/3 validated key storage and can perform cryptographic operations without exposing private keys. This directly addresses the requirement to prevent key extraction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KMS

    Why it's wrong here

    KMS is a managed key-management service, not hardware in the deployment path, so it cannot prevent extraction of keys used for TLS termination. It is tempting because it generates and stores keys, and would be correct for envelope encryption of data at rest, but the question specifies a hardware solution.

  • ✗

    TPM

    Why it's wrong here

    A TPM is a motherboard-bound chip that seals keys to a specific host's boot state; it cannot serve TLS termination keys across a server fleet or resist extraction by a privileged local attacker. It is tempting as dedicated key hardware, and suits disk encryption or platform attestation.

  • ✗

    UEFI

    Why it's wrong here

    UEFI is firmware that verifies boot components; it holds no key store and cannot isolate TLS private keys from extraction. It is tempting as a hardware root of trust, and would be correct for secure boot integrity, but key protection demands a tamper-resistant cryptographic module such as an HSM.

  • ✓

    HSM

    Why this is correct

    A hardware security module performs cryptographic operations internally, so private keys never leave the tamper-resistant boundary — satisfying the requirement to prevent key extraction during TLS termination. Unlike software keystores or TPMs, an HSM is purpose-built for high-volume server-side TLS, keeping keys non-exportable while Microsoft Entra ID governs access.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.