CISSP Security Architecture and Engineering Practice Question
Which of the following is a primary function of a Trusted Platform Module (TPM)?
⚠ Common exam trap
CISSP often tests the misconception that a TPM encrypts network traffic or enforces access control, when its primary role is secure cryptographic key storage and platform integrity measurement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Storing cryptographic keys securely
A Trusted Platform Module (TPM) is a hardware chip that securely stores cryptographic keys, certificates, and measurements used for platform integrity and encryption. Its primary function is secure key storage and cryptographic operations, such as protecting BitLocker keys and enabling measured boot. Option D correctly identifies this core capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypting network traffic
Why it's wrong here
A Trusted Platform Module (TPM) is a hardware security module designed for platform integrity and secure key storage, not for the real-time encryption and decryption of network traffic. Network encryption, such as that provided by TLS (Transport Layer Security) or IPsec (Internet Protocol Security), operates at higher layers of the network stack and is typically handled by software libraries or dedicated network hardware. While a TPM can securely store the cryptographic keys used by TLS or IPsec, it does not directly perform the ongoing data encryption or decryption for network communications.
- ✗
Providing antivirus protection
Why it's wrong here
Providing antivirus protection is a function of specialized software applications designed to detect, prevent, and remove malicious software from a computer system. A Trusted Platform Module (TPM), conversely, is a hardware component embedded in a computer system that focuses on platform integrity, secure boot processes, and cryptographic operations. While a TPM can contribute to a more secure system environment that makes it harder for malware to persist, it does not actively scan for, identify, or remediate viruses or other forms of malware.
- ✗
Enforcing access control policies
Why it's wrong here
Enforcing access control policies is primarily the responsibility of the operating system's security kernel or dedicated access control mechanisms, which determine user and process permissions to system resources. A Trusted Platform Module (TPM) does not directly manage user identities or resource permissions within an operating system. While a TPM can contribute to the overall security posture by ensuring system integrity and securely storing authentication credentials, it does not actively grant or deny access to files, directories, or system functions based on defined policies.
- ✓
Storing cryptographic keys securely
Why this is correct
Storing cryptographic keys securely is a core and primary function of a Trusted Platform Module (TPM). The TPM provides a tamper-resistant environment, often isolated from the main CPU, where sensitive cryptographic keys can be generated, stored, and used without being exposed to software vulnerabilities or physical attacks on the host system. This secure storage protects keys from unauthorized access and ensures their integrity, which is crucial for secure boot, disk encryption, and digital signing operations.
Go deeper
Related to this question
Learn chapter
Security Operations Foundations
Key term
Trusted Platform Module
A Trusted Platform Module (TPM) is a dedicated microcontroller chip that securely stores cryptographic keys, passwords, and certificates to protect a computer's hardware and ensure system integrity.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.