Courseiva

SSCP Systems and Application Security Practice Question

A security administrator is deploying a new web application on a Linux server and wants to prevent an attacker who compromises the web server process from reading the application's private TLS keys stored on the same host. The administrator decides to use a hardware security module (HSM) to protect the keys. Which of the following BEST describes how the HSM provides this protection?

⚠ Common exam trap

Candidates often confuse encryption of a key at rest with isolation of the key from the host, since a compromised process can read a decrypted key from memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The HSM performs cryptographic operations internally so the private key never leaves the hardware boundary.

A hardware security module protects private keys by generating and using them inside tamper-resistant hardware. The key never enters the host's memory or file system, so a compromised web server process cannot read it. Encrypting keys on disk, using a TPM, or replicating keys to a CPU enclave still exposes the key material to the host at some point, which fails the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The HSM stores the private keys in a file encrypted with a passphrase that only the web server process knows.

    Why it's wrong here

    Storing keys in a passphrase-encrypted file still places the decryption material on the host. If the web server process is compromised, the attacker can potentially capture the passphrase from memory or the process environment and decrypt the key file. This does not provide the hardware isolation that prevents key extraction, so it fails the requirement.

  • ✗

    The HSM encrypts the private key with a key derived from the server's TPM and stores the ciphertext on disk.

    Why it's wrong here

    Using a TPM-derived key to encrypt the private key at rest protects against offline disk theft, but once the web server starts, it must decrypt the key into memory to use it. A compromised web server process could then read the decrypted key from memory. This approach does not prevent key extraction by a process-level attacker.

  • ✓

    The HSM performs cryptographic operations internally so the private key never leaves the hardware boundary.

    Why this is correct

    An HSM generates and stores private keys in tamper-resistant hardware and performs signing or decryption operations internally. The web server sends data to the HSM and receives the result, but the private key itself is never exposed to the host memory or file system. Even if the web server process is compromised, the attacker cannot extract the key from the HSM.

  • ✗

    The HSM replicates the private key to a secure enclave in the server CPU, where it is used for TLS handshakes.

    Why it's wrong here

    Replicating the private key to a CPU enclave still copies the key material outside the HSM boundary. A compromised host could potentially access the enclave through side-channel attacks or memory inspection. The core benefit of an HSM is that the key never leaves the hardware module, so replication undermines the protection described in the scenario.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.