CompTIA SecurityX (CAS-005)Security EngineeringEasy
A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements and the need for high-assurance protection of cryptographic keys, the organization must ensure that all master encryption keys are generated, stored, and used within a tamper-resistant, FIPS 140-2 Level 3 compliant environment. Which specialized hardware device is MOST appropriate for meeting this requirement?
- ATrusted Platform Module (TPM)
- BSmart Card
- CField-Programmable Gate Array (FPGA)
- DHardware Security Module (HSM)
Show answer & explanationAnswer & explanation
Correct answer: D. Hardware Security Module (HSM)
A Hardware Security Module (HSM) is a dedicated cryptographic processor designed to protect cryptographic keys and perform cryptographic operations within a secure, tamper-resistant environment. FIPS 140-2 Level 3 compliance is a common requirement for HSMs in high-security applications like financial services.
Why the other options are wrong
- A. A TPM provides hardware-based security functions, primarily for platform integrity and key storage, but typically not the high-volume, FIPS 140-2 Level 3 tamper-resistance required for master encryption keys in a payment system.
- B. Smart cards are portable devices for user authentication and key storage, not for managing master encryption keys for a large-scale payment system.
- C. An FPGA is a reconfigurable integrated circuit used for custom hardware logic, not a standard device for secure cryptographic key management.
Hardware Security Module (HSM)
A physical computing device that safeguards and manages digital keys, performs cryptographic functions, and provides a tamper-resistant environment for sensitive operations.
- Protects cryptographic keys in hardware
- Provides tamper-resistance and FIPS compliance
- Used for master keys, certificate authorities, payment systems
Memory trick: HSM: Holds Secrets Magnificently!