Courseiva

CISSP Security Architecture and Engineering Practice Question

Which of the following are characteristics of a Trusted Execution Environment (TEE)? (Choose TWO)

⚠ Common exam trap

CISSP often tests the misconception that a TEE requires a TPM or is a cloud-only construct, when in fact the defining traits are hardware isolation from the OS and protection even against the OS itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides hardware-enforced isolation from the main OS

Option D is correct because a TEE, such as Intel SGX enclaves or ARM TrustZone secure world, relies on CPU hardware mechanisms to create an isolated execution context that is separated from the rich operating system, so the main OS cannot access the enclave's memory. Option E is correct because the whole purpose of a TEE is to keep code and data confidential and integrity-protected even against a compromised or malicious host OS, hypervisor, or other privileged software, using hardware-based memory encryption and access control. Option A is incorrect because TEEs are available on client devices, mobile phones, and embedded systems, not only in cloud environments. Option B is incorrect because a TEE is not a separate virtual machine; it is a hardware-isolated execution environment within a processor, distinct from VM-based isolation. Option C is incorrect because a TEE does not require a discrete TPM chip; it uses CPU-level features, and a TPM is a separate component for key storage and attestation, not a prerequisite for a TEE.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is only available in cloud environments

    Why it's wrong here

    Trusted Execution Environments (TEEs) are not exclusive to cloud environments; they are widely implemented across various computing platforms. Modern smartphones, IoT devices, and embedded systems frequently incorporate TEEs, such as ARM TrustZone, to secure sensitive operations directly on the device hardware. This pervasive deployment demonstrates their utility beyond just large-scale cloud infrastructure.

  • ✗

    It runs as a separate virtual machine

    Why it's wrong here

    A Trusted Execution Environment (TEE) does not operate as a separate, full-fledged virtual machine. Instead, a TEE is a hardware-backed secure area within a main processor, designed to run small, isolated applications or trusted apps. Unlike a general-purpose VM that hosts an entire operating system, a TEE provides a minimal, secure execution environment with limited resources, focusing on specific security-critical tasks.

  • ✗

    It requires a TPM chip

    Why it's wrong here

    A Trusted Execution Environment (TEE) does not inherently require a Trusted Platform Module (TPM) chip, as they serve distinct but complementary security functions. While a TPM provides secure storage for cryptographic keys and performs platform integrity measurements, a TEE creates an isolated execution environment for code and data. TEEs typically rely on dedicated secure hardware extensions, like ARM TrustZone or Intel SGX, rather than a separate TPM chip for their core isolation capabilities.

  • ✓

    It provides hardware-enforced isolation from the main OS

    Why this is correct

    A fundamental characteristic of a Trusted Execution Environment (TEE) is its ability to provide robust hardware-enforced isolation from the main operating system. This isolation ensures that code and data running within the TEE are protected from unauthorized access or tampering by the rich OS, hypervisor, or any other software running in the less privileged 'normal world.' This hardware-level separation is critical for maintaining the integrity and confidentiality of sensitive computations.

  • ✓

    It protects code and data from unauthorized access even by the OS

    Why this is correct

    A key benefit of a Trusted Execution Environment (TEE) is its capacity to protect sensitive code and data from unauthorized access, even by a potentially compromised main operating system or hypervisor. By executing within a secure, isolated hardware enclave, the TEE ensures that critical intellectual property, cryptographic keys, or personal data remain confidential and their integrity is preserved. This strong protection extends beyond software vulnerabilities, safeguarding against malicious actors who might gain control over the primary OS.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.