CompTIA SecurityX (CAS-005)Security EngineeringMedium
A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements, all encryption keys used for customer transaction data must be protected against both logical and physical compromise, and their lifecycle must be managed according to FIPS 140-2 Level 3 standards. The solution must also support high transaction volumes. Which specialized hardware device is BEST suited to meet these requirements?
- AField-Programmable Gate Array (FPGA)
- BTrusted Platform Module (TPM)
- CHardware Security Module (HSM)
- DSecure Enclave Processor
Show answer & explanationAnswer & explanation
Correct answer: C. Hardware Security Module (HSM)
A Hardware Security Module (HSM) is specifically designed to meet FIPS 140-2 Level 3 (or higher) cryptographic module standards, providing robust logical and physical tamper protection for cryptographic keys and operations. HSMs are built for high-performance cryptographic operations, making them ideal for high-volume transaction processing in regulated environments.
Why the other options are wrong
- A. An FPGA is used for custom hardware logic and acceleration, but it does not inherently provide the FIPS 140-2 compliant key management and tamper resistance of an HSM.
- B. A TPM provides hardware-based security for a single host, typically FIPS 140-2 Level 1 or 2, and is not designed for high-volume centralized key management.
- D. A Secure Enclave Processor provides a secure execution environment within a general-purpose CPU but typically lacks the FIPS 140-2 Level 3 physical tamper protection and dedicated high-volume crypto acceleration of an HSM.
Hardware Security Module (HSM)
A Hardware Security Module (HSM) is a physical computing device that safeguards and manages digital keys, performs cryptographic operations, and provides strong authentication within a tamper-resistant environment.
- FIPS 140-2 validated, often Level 3 or higher.
- Protects keys from logical and physical attacks.
- Designed for high-performance, high-volume cryptographic operations.
Memory trick: HSM: high security, high volume, high compliance.