CompTIA Security+ (SY0-701)Security ArchitectureHard

A financial institution must ensure that private encryption keys used to protect customer data are generated, stored, and used only within tamper-resistant hardware, and are never exposed in plaintext to the operating system. Which of the following solutions BEST meets this requirement?

  1. AAn encrypted configuration file stored in a version-controlled repository
  2. BA trusted platform module (TPM) embedded in employee laptops
  3. CA hardware security module (HSM)
  4. DA software-based key management service running on the application server
Show answer & explanation

Correct answer: C. A hardware security module (HSM)

A hardware security module (HSM) is a dedicated, tamper-resistant physical device designed to generate, store, and manage cryptographic keys, performing cryptographic operations internally so that private keys never leave the device in plaintext, making it ideal for high-assurance environments like financial institutions.

Why the other options are wrong

  • A. An encrypted config file still requires the decryption key to exist somewhere accessible, defeating the purpose.
  • B. TPMs secure device-level keys (e.g., disk encryption) but are not designed for centralized enterprise key management at this scale.
  • D. Software-based key management typically exposes keys in server memory, lacking hardware-level tamper resistance.

Hardware Security Module (HSM)

A dedicated, tamper-resistant hardware device used to generate, store, and manage cryptographic keys and perform cryptographic operations without exposing private keys in plaintext.

  • Keys never leave the HSM in unencrypted form.
  • Often used for PKI, payment processing, and regulatory compliance.
  • Different from TPM, which secures individual endpoint devices, not enterprise-scale key management.

Memory trick: HSM is the vault where keys are born and die, never leaving.

More Security Architecture questions