CompTIA SecurityX (CAS-005)Security EngineeringMedium

A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements and the need for maximum security for cryptographic keys, the architect must ensure that all master encryption keys are generated, stored, and used within a tamper-resistant and FIPS 140-2 Level 3 compliant hardware device. Which of the following technologies is BEST suited for this purpose?

  1. AHardware Security Module (HSM)
  2. BSecure Enclave
  3. CField-Programmable Gate Array (FPGA)
  4. DTrusted Platform Module (TPM)
Show answer & explanation

Correct answer: A. Hardware Security Module (HSM)

A Hardware Security Module (HSM) is a dedicated physical computing device that safeguards and manages digital keys, performs cryptographic operations, and is designed to be tamper-resistant and FIPS 140-2 Level 3 (or higher) compliant, making it ideal for high-assurance key management.

Why the other options are wrong

  • B. Secure Enclaves (e.g., Apple Secure Enclave, Intel SGX) provide isolated execution environments on general-purpose CPUs, offering strong protection for code and data, but dedicated HSMs typically provide higher FIPS compliance levels and tamper resistance specifically for cryptographic key management.
  • C. FPGAs are reconfigurable integrated circuits, used for custom hardware acceleration, but they are not inherently secure key storage or cryptographic devices like HSMs.
  • D. TPMs provide hardware-based security functions but are typically integrated into endpoints (laptops, servers) and generally offer lower FIPS compliance levels and less robust tamper resistance compared to dedicated HSMs.

Hardware Security Module (HSM)

A physical computing device that protects digital keys and performs cryptographic operations within a tamper-resistant environment, often FIPS 140-2 certified.

  • Generates, stores, and protects cryptographic keys
  • Performs cryptographic operations securely
  • Tamper-resistant and FIPS 140-2 certified (often Level 3+)

Memory trick: HSM: Holds Secure Masterkeys.

More Security Engineering questions