Courseiva
Cryptography →hardMultiple Select

SSCP Cryptography Practice Question

A company is deploying a hardware security module (HSM) to protect the root keys of its certificate authority. Which two practices are essential for maintaining the security of the CA's private keys? (Choose two.)

⚠ Common exam trap

The trap here is treating encrypted key backups or convenient remote administration as acceptable for a root CA, when they actually expand the attack surface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the CA private keys in the HSM and configure it to prevent export of the keys in plaintext.

Protecting a CA's private keys requires keeping them inside a tamper-resistant HSM and preventing plaintext export, as well as enforcing multi-person control over signing operations. Exporting keys to a file, exposing administration to the internet, or merging root and issuing roles all increase the risk of key compromise. These practices reflect standard CA hardening guidance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable remote administration of the HSM over the public internet for convenience.

    Why it's wrong here

    Exposing HSM administration to the public internet greatly increases the risk of unauthorized access and attack. Administrative interfaces should be restricted to a dedicated, isolated management network with strong authentication. Convenience does not justify weakening the security perimeter around a CA's most sensitive component.

  • ✓

    Store the CA private keys in the HSM and configure it to prevent export of the keys in plaintext.

    Why this is correct

    Keeping the CA private keys inside the HSM and preventing plaintext export ensures that the keys never exist in an unprotected form on general-purpose systems. This reduces the risk of theft or accidental disclosure and is a fundamental requirement for protecting a root CA. The HSM's tamper-resistant design provides additional safeguards against physical and logical attacks.

  • ✗

    Back up the CA private keys by exporting them to an encrypted file on a network share.

    Why it's wrong here

    Exporting CA private keys to a file, even if encrypted, creates a copy outside the HSM and expands the attack surface. If the encryption key or the file is compromised, the CA is compromised. Secure backup should use HSM-supported mechanisms such as key wrapping or a backup HSM, not a general-purpose network share.

  • ✓

    Require multiple authorized administrators to authenticate before the HSM performs a signing operation.

    Why this is correct

    Enforcing multi-person authentication for signing operations reduces the risk of insider misuse and ensures that no single administrator can issue certificates without oversight. This is a common control for high-value CAs and aligns with separation-of-duties principles. It also provides accountability, since the HSM can log which administrators authorized each operation.

  • ✗

    Use the same HSM partition for the root CA and for issuing subordinate certificates to simplify management.

    Why it's wrong here

    The root CA key should be kept offline and used only to sign subordinate CA certificates, not for routine issuance. Combining root and issuing functions in one partition increases exposure of the root key and violates the principle of least privilege. Separation allows the root to remain protected while subordinate CAs handle day-to-day signing.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.