CompTIA Security+ (SY0-701)Security ArchitectureHard
A financial institution must ensure that private encryption keys used to protect customer data are generated, stored, and used only within tamper-resistant hardware, and are never exposed in plaintext to the operating system. Which of the following solutions BEST meets this requirement?
- AAn encrypted configuration file stored in a version-controlled repository
- BA trusted platform module (TPM) embedded in employee laptops
- CA hardware security module (HSM)
- DA software-based key management service running on the application server
Show answer & explanationAnswer & explanation
Correct answer: C. A hardware security module (HSM)
A hardware security module (HSM) is a dedicated, tamper-resistant physical device designed to generate, store, and manage cryptographic keys, performing cryptographic operations internally so that private keys never leave the device in plaintext, making it ideal for high-assurance environments like financial institutions.
Why the other options are wrong
- A. An encrypted config file still requires the decryption key to exist somewhere accessible, defeating the purpose.
- B. TPMs secure device-level keys (e.g., disk encryption) but are not designed for centralized enterprise key management at this scale.
- D. Software-based key management typically exposes keys in server memory, lacking hardware-level tamper resistance.
Hardware Security Module (HSM)
A dedicated, tamper-resistant hardware device used to generate, store, and manage cryptographic keys and perform cryptographic operations without exposing private keys in plaintext.
- Keys never leave the HSM in unencrypted form.
- Often used for PKI, payment processing, and regulatory compliance.
- Different from TPM, which secures individual endpoint devices, not enterprise-scale key management.
Memory trick: HSM is the vault where keys are born and die, never leaving.