CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing a key management system for a global enterprise that processes vast amounts of cryptographic operations daily. The system must provide FIPS 140-2 Level 3 validated protection for cryptographic keys, ensure high performance for signing and encryption operations, and offer robust tamper-resistance. What type of device is BEST suited to meet these stringent requirements?
- ATrusted Platform Module (TPM)
- BSoftware Key Store
- CHardware Security Module (HSM)
- DVirtual Machine (VM) Disk Encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Hardware Security Module (HSM)
A Hardware Security Module (HSM) is a dedicated physical computing device that safeguards and manages digital keys, performs cryptographic operations, and meets high-level security standards like FIPS 140-2 Level 3, offering tamper-resistance and high performance.
Why the other options are wrong
- A. A TPM provides hardware-based security for a single host, offering FIPS 140-2 Level 1 or 2, but lacks the high-performance and scalability for a global enterprise's vast cryptographic operations.
- B. A software key store is purely software-based, offering the lowest level of protection and no FIPS 140-2 physical security validation.
- D. VM disk encryption protects data at rest on a virtual disk but does not provide protection for cryptographic keys themselves during use or high-performance cryptographic operations for a KMS.
Hardware Security Module (HSM)
A physical computing device that safeguards and manages digital keys, performs cryptographic operations, and provides a protected, tamper-resistant environment for sensitive data and operations.
- FIPS 140-2 Level 3+ validated
- Tamper-resistant physical device
- High performance for cryptographic operations
Memory trick: HSMs Hold Keys in Hardened, High-Security Vaults.