CISSP Security Architecture and Engineering Practice Question
Which of the following are characteristics of a Trusted Execution Environment (TEE)? (Choose TWO)
⚠ Common exam trap
CISSP often tests the misconception that a TEE requires a TPM or is a cloud-only construct, when in fact the defining traits are hardware isolation from the OS and protection even against the OS itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides hardware-enforced isolation from the main OS
Option D is correct because a TEE, such as Intel SGX enclaves or ARM TrustZone secure world, relies on CPU hardware mechanisms to create an isolated execution context that is separated from the rich operating system, so the main OS cannot access the enclave's memory. Option E is correct because the whole purpose of a TEE is to keep code and data confidential and integrity-protected even against a compromised or malicious host OS, hypervisor, or other privileged software, using hardware-based memory encryption and access control. Option A is incorrect because TEEs are available on client devices, mobile phones, and embedded systems, not only in cloud environments. Option B is incorrect because a TEE is not a separate virtual machine; it is a hardware-isolated execution environment within a processor, distinct from VM-based isolation. Option C is incorrect because a TEE does not require a discrete TPM chip; it uses CPU-level features, and a TPM is a separate component for key storage and attestation, not a prerequisite for a TEE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is only available in cloud environments
Why it's wrong here
Trusted Execution Environments (TEEs) are not exclusive to cloud environments; they are widely implemented across various computing platforms. Modern smartphones, IoT devices, and embedded systems frequently incorporate TEEs, such as ARM TrustZone, to secure sensitive operations directly on the device hardware. This pervasive deployment demonstrates their utility beyond just large-scale cloud infrastructure.
- ✗
It runs as a separate virtual machine
Why it's wrong here
A Trusted Execution Environment (TEE) does not operate as a separate, full-fledged virtual machine. Instead, a TEE is a hardware-backed secure area within a main processor, designed to run small, isolated applications or trusted apps. Unlike a general-purpose VM that hosts an entire operating system, a TEE provides a minimal, secure execution environment with limited resources, focusing on specific security-critical tasks.
- ✗
It requires a TPM chip
Why it's wrong here
A Trusted Execution Environment (TEE) does not inherently require a Trusted Platform Module (TPM) chip, as they serve distinct but complementary security functions. While a TPM provides secure storage for cryptographic keys and performs platform integrity measurements, a TEE creates an isolated execution environment for code and data. TEEs typically rely on dedicated secure hardware extensions, like ARM TrustZone or Intel SGX, rather than a separate TPM chip for their core isolation capabilities.
- ✓
It provides hardware-enforced isolation from the main OS
Why this is correct
A fundamental characteristic of a Trusted Execution Environment (TEE) is its ability to provide robust hardware-enforced isolation from the main operating system. This isolation ensures that code and data running within the TEE are protected from unauthorized access or tampering by the rich OS, hypervisor, or any other software running in the less privileged 'normal world.' This hardware-level separation is critical for maintaining the integrity and confidentiality of sensitive computations.
- ✓
It protects code and data from unauthorized access even by the OS
Why this is correct
A key benefit of a Trusted Execution Environment (TEE) is its capacity to protect sensitive code and data from unauthorized access, even by a potentially compromised main operating system or hypervisor. By executing within a secure, isolated hardware enclave, the TEE ensures that critical intellectual property, cryptographic keys, or personal data remain confidential and their integrity is preserved. This strong protection extends beyond software vulnerabilities, safeguarding against malicious actors who might gain control over the primary OS.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.