CISSP Security Architecture and Engineering Practice Question
A security engineer is evaluating a system that uses a cryptographic module validated under FIPS 140-2. The module provides encryption and key management services. The engineer notes that the module's cryptographic boundary is defined, and it includes a hardware component that stores keys. The engineer must ensure that the module's keys are protected against unauthorized disclosure even if the host operating system is compromised. Which aspect of the module's design is most critical to achieving this protection?
⚠ Common exam trap
The trap here is focusing on the strength of the cryptographic algorithm or the randomness of key generation, when the real issue is where the keys are stored and processed relative to the compromised host OS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The module's cryptographic boundary includes a hardware security module (HSM) that performs key storage and cryptographic operations internally.
The most critical aspect is the hardware security module (HSM) within the cryptographic boundary, which stores and processes keys internally. This ensures that keys are never exposed to the host OS, so even if the OS is compromised, the keys remain protected. A software implementation, strong algorithms, or entropy seeding do not provide the same level of isolation and are insufficient when the host OS is untrusted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The module uses a software-based cryptographic algorithm implementation that runs in the host OS's user space.
Why it's wrong here
A software-based implementation running in user space is vulnerable if the host OS is compromised, because an attacker with OS-level access could potentially read memory, inject code, or intercept keys. Even if the algorithm is strong, the keys are not isolated from the compromised OS. This design does not provide the hardware-based protection needed to safeguard keys when the host OS is untrusted, so it fails the requirement.
- ✓
The module's cryptographic boundary includes a hardware security module (HSM) that performs key storage and cryptographic operations internally.
Why this is correct
An HSM within the cryptographic boundary stores and processes keys internally, isolating them from the host OS. Even if the host OS is compromised, the attacker cannot directly access the keys because they never leave the HSM's protected environment. Cryptographic operations are performed inside the HSM, and only results are returned. This hardware isolation is critical to protecting keys against unauthorized disclosure when the host OS is compromised.
- ✗
The module performs key generation using a random number generator that is seeded from the host OS's entropy pool.
Why it's wrong here
Seeding a random number generator from the host OS's entropy pool can be risky if the host OS is compromised, because the attacker might influence or predict the entropy. Even if the generated keys are strong, their storage and use are not protected by this alone. This does not provide the hardware isolation needed to keep keys secure when the host OS is untrusted, so it is not the most critical aspect for protecting keys.
- ✗
The module uses a FIPS-approved algorithm such as AES-256 for encryption.
Why it's wrong here
Using a FIPS-approved algorithm like AES-256 ensures strong encryption, but it does not protect the keys themselves if the host OS is compromised. If the keys are stored or processed in software outside a protected boundary, an attacker with OS access could extract them. The algorithm choice is important for cryptographic strength, but it is not the critical aspect for protecting keys against a compromised host OS.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.