Courseiva
Cryptography →hardMultiple Choice

GSEC Cryptography Practice Question

A security architect is designing a system that requires cryptographic keys to be generated, stored, and used without ever exposing the private key material to the operating system. The keys must be usable for TLS server authentication and must support high transaction volumes. Which of the following solutions BEST meets these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse a TPM with an HSM; TPMs are for platform integrity and low-volume crypto, not high-performance TLS key protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Hardware Security Module (HSM) with TLS offloading capabilities.

An HSM provides a dedicated, tamper-resistant environment where private keys are generated and used without ever leaving the device. This ensures the operating system never sees the key material. HSMs are also designed for high-performance cryptographic operations, including TLS acceleration, making them ideal for high-volume server authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A cloud key management service (KMS) that stores keys in a multi-tenant environment.

    Why it's wrong here

    Cloud KMS solutions can protect keys, but multi-tenant environments may not guarantee that private keys never leave the hardware boundary; some services export keys or use software-based protections. The requirement explicitly states keys must never be exposed to the OS, which may not be guaranteed. Additionally, high transaction volumes may incur latency and cost issues compared to a dedicated HSM.

  • ✓

    A Hardware Security Module (HSM) with TLS offloading capabilities.

    Why this is correct

    An HSM is a dedicated hardware device that generates, stores, and uses cryptographic keys within a tamper-resistant boundary. Private keys never leave the HSM in plaintext, so the operating system cannot access them. HSMs support high-performance TLS acceleration, making them suitable for high transaction volumes. This meets all requirements: key isolation and performance.

  • ✗

    A software-based key store protected by a strong passphrase and file system permissions.

    Why it's wrong here

    Software-based key stores keep private keys in memory or on disk, where the operating system and privileged processes can access them. Even with strong passphrase protection, the key material is exposed to the OS during use, violating the requirement. This approach also lacks hardware isolation and is vulnerable to memory scraping or cold boot attacks.

  • ✗

    A Trusted Platform Module (TPM) 2.0 chip on each server.

    Why it's wrong here

    A TPM provides secure storage and cryptographic operations, but it is designed for platform integrity and low-throughput operations, not high-volume TLS server authentication. TPMs typically have limited performance and may not support the required number of TLS handshakes. They also do not provide the same level of physical tamper resistance as an HSM for server key protection.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.