Courseiva
Security Architecture and EngineeringmediumMultiple SelectObjective-mapped

CISSP Security Architecture and Engineering Practice Question

A company is designing a secure application that requires hardware-based key storage and remote attestation. Which THREE technologies provide hardware root of trust? Select three.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Hardware Security Module (HSM)

TPM, TEE (e.g., Intel SGX, ARM TrustZone), and HSM provide hardware-based security functions and root of trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Virtual Trusted Platform Module (vTPM)

    Why it's wrong here

    A Virtual Trusted Platform Module (vTPM) is a software-based emulation of a physical TPM, typically deployed in virtualized environments. While it offers some cryptographic functions and secure storage within the virtual machine's context, its security fundamentally relies on the integrity of the underlying hypervisor and host hardware. Consequently, a vTPM does not provide a true hardware root of trust directly to the guest VM, making it less suitable when the highest level of hardware-backed assurance is explicitly required for a secure application.

  • Hardware Security Module (HSM)

    Why this is correct

    A Hardware Security Module (HSM) is a dedicated physical computing device designed to protect cryptographic keys and perform cryptographic operations within a tamper-resistant and tamper-evident environment. It establishes a strong hardware root of trust, ensuring the integrity and confidentiality of critical keys even against sophisticated physical attacks. HSMs are essential for high-assurance applications requiring secure key generation, storage, and management, making them a cornerstone for robust cryptographic security and compliance.

  • Software Guard Extensions (SGX)

    Why it's wrong here

    Intel Software Guard Extensions (SGX) is a specific implementation of a Trusted Execution Environment (TEE) that allows applications to create private regions of code and data, called enclaves, in memory. While SGX provides strong isolation and protection against software attacks, selecting it alongside the broader "Trusted Execution Environment (TEE)" option would be redundant. The question asks for distinct technologies, and TEE encompasses SGX as one of its forms, making SGX a less appropriate choice when TEE is already available as a more general category.

  • Trusted Execution Environment (TEE)

    Why this is correct

    A Trusted Execution Environment (TEE) is an isolated processing environment that runs alongside the main operating system, providing a higher level of security for sensitive data and code. It ensures the confidentiality and integrity of operations performed within its secure enclave, even if the main OS is compromised. TEEs are crucial for secure applications needing to protect intellectual property, perform secure payments, or handle biometric data by isolating critical computations from the potentially vulnerable rich operating system.

  • Trusted Platform Module (TPM)

    Why this is correct

    A Trusted Platform Module (TPM) is a secure cryptoprocessor integrated into a computer's motherboard, providing hardware-based security functions. It offers secure storage for cryptographic keys, platform integrity measurements, and attestation capabilities, enabling secure boot processes and verifying the system's state. TPMs are fundamental for establishing a hardware root of trust for the platform, binding keys to specific system configurations, and enhancing overall system security against tampering and unauthorized modifications.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.