CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a key management system for a global enterprise that processes vast amounts of cryptographic operations daily. The system must provide FIPS 140-2 Level 3 validated protection for cryptographic keys, ensure high performance for signing and encryption operations, and offer robust tamper-resistance. What type of device is BEST suited to meet these stringent requirements?

  1. ATrusted Platform Module (TPM)
  2. BSoftware Key Store
  3. CHardware Security Module (HSM)
  4. DVirtual Machine (VM) Disk Encryption
Show answer & explanation

Correct answer: C. Hardware Security Module (HSM)

A Hardware Security Module (HSM) is a dedicated physical computing device that safeguards and manages digital keys, performs cryptographic operations, and meets high-level security standards like FIPS 140-2 Level 3, offering tamper-resistance and high performance.

Why the other options are wrong

  • A. A TPM provides hardware-based security for a single host, offering FIPS 140-2 Level 1 or 2, but lacks the high-performance and scalability for a global enterprise's vast cryptographic operations.
  • B. A software key store is purely software-based, offering the lowest level of protection and no FIPS 140-2 physical security validation.
  • D. VM disk encryption protects data at rest on a virtual disk but does not provide protection for cryptographic keys themselves during use or high-performance cryptographic operations for a KMS.

Hardware Security Module (HSM)

A physical computing device that safeguards and manages digital keys, performs cryptographic operations, and provides a protected, tamper-resistant environment for sensitive data and operations.

  • FIPS 140-2 Level 3+ validated
  • Tamper-resistant physical device
  • High performance for cryptographic operations

Memory trick: HSMs Hold Keys in Hardened, High-Security Vaults.

More Security Engineering questions