CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security engineer is tasked with hardening a critical Linux server that processes sensitive financial transactions. The organization requires that all sensitive data residing on the server's storage be encrypted at rest, and that the encryption keys themselves must be protected against compromise even if the server's operating system is breached. Which of the following technologies would BEST meet these requirements for key protection?
- ATPM (Trusted Platform Module)
- BOpenSSL
- CLUKS (Linux Unified Key Setup)
- DGnuPG (GNU Privacy Guard)
Show answer & explanationAnswer & explanation
Correct answer: A. TPM (Trusted Platform Module)
A Trusted Platform Module (TPM) is a hardware-based security component that provides cryptographic functions and securely stores cryptographic keys. It can protect keys from software attacks and unauthorized access, even if the operating system is compromised, by binding them to specific hardware and boot states.
Why the other options are wrong
- B. OpenSSL is a software library for cryptographic functions; it does not provide hardware-level protection for keys.
- C. LUKS is a disk encryption specification for Linux, but it relies on software-based key management unless integrated with a hardware module like a TPM.
- D. GnuPG is a software suite for encryption and digital signatures; it does not provide hardware-level protection for keys.
Trusted Platform Module (TPM)
A secure cryptoprocessor that stores cryptographic keys and offers security services such as platform integrity verification and hardware-based encryption key generation/storage.
- Hardware-based security
- Stores cryptographic keys securely
- Protects against software attacks
- Verifies platform integrity
Memory trick: TPM: Trust in hardware for key protection.