Courseiva
Security Architecture and EngineeringeasyMultiple ChoiceObjective-mapped

CISSP Security Architecture and Engineering Practice Question

Which of the following is a primary function of a Trusted Platform Module (TPM)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Storing cryptographic keys securely

A TPM provides hardware-based secure storage for cryptographic keys, enabling secure boot and remote attestation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Encrypting network traffic

    Why it's wrong here

    A Trusted Platform Module (TPM) is a hardware security module designed for platform integrity and secure key storage, not for the real-time encryption and decryption of network traffic. Network encryption, such as that provided by TLS (Transport Layer Security) or IPsec (Internet Protocol Security), operates at higher layers of the network stack and is typically handled by software libraries or dedicated network hardware. While a TPM can securely store the cryptographic keys used by TLS or IPsec, it does not directly perform the ongoing data encryption or decryption for network communications.

  • Providing antivirus protection

    Why it's wrong here

    Providing antivirus protection is a function of specialized software applications designed to detect, prevent, and remove malicious software from a computer system. A Trusted Platform Module (TPM), conversely, is a hardware component embedded in a computer system that focuses on platform integrity, secure boot processes, and cryptographic operations. While a TPM can contribute to a more secure system environment that makes it harder for malware to persist, it does not actively scan for, identify, or remediate viruses or other forms of malware.

  • Enforcing access control policies

    Why it's wrong here

    Enforcing access control policies is primarily the responsibility of the operating system's security kernel or dedicated access control mechanisms, which determine user and process permissions to system resources. A Trusted Platform Module (TPM) does not directly manage user identities or resource permissions within an operating system. While a TPM can contribute to the overall security posture by ensuring system integrity and securely storing authentication credentials, it does not actively grant or deny access to files, directories, or system functions based on defined policies.

  • Storing cryptographic keys securely

    Why this is correct

    Storing cryptographic keys securely is a core and primary function of a Trusted Platform Module (TPM). The TPM provides a tamper-resistant environment, often isolated from the main CPU, where sensitive cryptographic keys can be generated, stored, and used without being exposed to software vulnerabilities or physical attacks on the host system. This secure storage protects keys from unauthorized access and ensures their integrity, which is crucial for secure boot, disk encryption, and digital signing operations.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.