SSCP Cryptography Practice Question
A financial institution is deploying a hardware security module (HSM) to protect cryptographic keys used for payment transactions. The security team must ensure that the HSM provides strong logical and physical protection. Which two of the following characteristics are MOST important to validate when selecting the HSM? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse operational features such as scalability, automatic updates, or power redundancy with the core security validations that actually protect cryptographic keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The HSM enforces role-based access control and requires multiple physical or logical credentials for administrative actions.
Validating a FIPS 140-2/140-3 certificate at an appropriate level confirms that the HSM meets stringent security requirements, including tamper resistance and key protection. Enforcing role-based access with multi-person control ensures that no single individual can compromise keys. Together, these characteristics provide the logical and physical safeguards needed for payment transaction keys, whereas capacity, automatic updates, and power backup do not directly address security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The HSM enforces role-based access control and requires multiple physical or logical credentials for administrative actions.
Why this is correct
Strong access control, especially multi-person integrity (split knowledge) for sensitive operations, prevents a single insider from extracting or misusing keys. This directly supports logical protection. Combined with physical tamper safeguards, role-based access with dual control is a critical capability to validate, because it limits the attack surface from authorized users and satisfies common audit requirements.
- ✗
The HSM includes a built-in UPS to maintain power during outages.
Why it's wrong here
A UPS addresses availability, not the logical or physical protection of keys. While availability is important for transaction processing, the question focuses on security characteristics. An uninterruptible power supply does not prevent key extraction, tampering, or unauthorized access. Therefore, it is not among the most important security validations when selecting an HSM for protecting payment keys.
- ✗
The HSM firmware can be updated automatically over the network without manual intervention.
Why it's wrong here
Automatic, unattended firmware updates can introduce risk if not cryptographically verified and controlled. A secure HSM should require authenticated, authorized firmware updates, often with dual control and signature verification. Unattended updates may allow a compromised update server to push malicious firmware, undermining the HSM's integrity. This is not a desirable security characteristic for a payment HSM.
- ✓
The HSM has a FIPS 140-2 or FIPS 140-3 validation at an appropriate security level.
Why this is correct
FIPS 140-2/140-3 validation independently confirms that the HSM meets defined security requirements for cryptographic modules, including key management, physical tamper evidence, and self-tests. For payment transactions, choosing a validated module at an appropriate level (e.g., Level 3 or 4) demonstrates due diligence and helps satisfy regulatory expectations. This is a primary criterion for trust in the module's protection.
- ✗
The HSM supports the largest possible number of symmetric key slots to avoid future purchases.
Why it's wrong here
Key capacity is a scalability consideration, not a security characteristic. While adequate slots are useful, an excessive number does not strengthen logical or physical protection. The question asks for the most important security validations; key slot count alone does not demonstrate tamper resistance, key zeroization, or validated cryptography, so it is not a primary criterion.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.