Courseiva

CISSP Security Architecture and Engineering Practice Question

A security engineer is evaluating a system that uses a cryptographic module validated under FIPS 140-2. The module provides encryption and key management services. The engineer notes that the module's cryptographic boundary is defined, and it includes a hardware component that stores keys. The engineer must ensure that the module's keys are protected against unauthorized disclosure even if the host operating system is compromised. Which aspect of the module's design is most critical to achieving this protection?

⚠ Common exam trap

The trap here is focusing on the strength of the cryptographic algorithm or the randomness of key generation, when the real issue is where the keys are stored and processed relative to the compromised host OS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The module's cryptographic boundary includes a hardware security module (HSM) that performs key storage and cryptographic operations internally.

The most critical aspect is the hardware security module (HSM) within the cryptographic boundary, which stores and processes keys internally. This ensures that keys are never exposed to the host OS, so even if the OS is compromised, the keys remain protected. A software implementation, strong algorithms, or entropy seeding do not provide the same level of isolation and are insufficient when the host OS is untrusted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The module uses a software-based cryptographic algorithm implementation that runs in the host OS's user space.

    Why it's wrong here

    A software-based implementation running in user space is vulnerable if the host OS is compromised, because an attacker with OS-level access could potentially read memory, inject code, or intercept keys. Even if the algorithm is strong, the keys are not isolated from the compromised OS. This design does not provide the hardware-based protection needed to safeguard keys when the host OS is untrusted, so it fails the requirement.

  • ✓

    The module's cryptographic boundary includes a hardware security module (HSM) that performs key storage and cryptographic operations internally.

    Why this is correct

    An HSM within the cryptographic boundary stores and processes keys internally, isolating them from the host OS. Even if the host OS is compromised, the attacker cannot directly access the keys because they never leave the HSM's protected environment. Cryptographic operations are performed inside the HSM, and only results are returned. This hardware isolation is critical to protecting keys against unauthorized disclosure when the host OS is compromised.

  • ✗

    The module performs key generation using a random number generator that is seeded from the host OS's entropy pool.

    Why it's wrong here

    Seeding a random number generator from the host OS's entropy pool can be risky if the host OS is compromised, because the attacker might influence or predict the entropy. Even if the generated keys are strong, their storage and use are not protected by this alone. This does not provide the hardware isolation needed to keep keys secure when the host OS is untrusted, so it is not the most critical aspect for protecting keys.

  • ✗

    The module uses a FIPS-approved algorithm such as AES-256 for encryption.

    Why it's wrong here

    Using a FIPS-approved algorithm like AES-256 ensures strong encryption, but it does not protect the keys themselves if the host OS is compromised. If the keys are stored or processed in software outside a protected boundary, an attacker with OS access could extract them. The algorithm choice is important for cryptographic strength, but it is not the critical aspect for protecting keys against a compromised host OS.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.