CompTIA SecurityX (CAS-005)Security EngineeringEasy

A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements and the need for high-assurance protection of cryptographic keys, the organization must ensure that all master encryption keys are generated, stored, and used within a tamper-resistant, FIPS 140-2 Level 3 compliant environment. Which specialized hardware device is MOST appropriate for meeting this requirement?

  1. ATrusted Platform Module (TPM)
  2. BSmart Card
  3. CField-Programmable Gate Array (FPGA)
  4. DHardware Security Module (HSM)
Show answer & explanation

Correct answer: D. Hardware Security Module (HSM)

A Hardware Security Module (HSM) is a dedicated cryptographic processor designed to protect cryptographic keys and perform cryptographic operations within a secure, tamper-resistant environment. FIPS 140-2 Level 3 compliance is a common requirement for HSMs in high-security applications like financial services.

Why the other options are wrong

  • A. A TPM provides hardware-based security functions, primarily for platform integrity and key storage, but typically not the high-volume, FIPS 140-2 Level 3 tamper-resistance required for master encryption keys in a payment system.
  • B. Smart cards are portable devices for user authentication and key storage, not for managing master encryption keys for a large-scale payment system.
  • C. An FPGA is a reconfigurable integrated circuit used for custom hardware logic, not a standard device for secure cryptographic key management.

Hardware Security Module (HSM)

A physical computing device that safeguards and manages digital keys, performs cryptographic functions, and provides a tamper-resistant environment for sensitive operations.

  • Protects cryptographic keys in hardware
  • Provides tamper-resistance and FIPS compliance
  • Used for master keys, certificate authorities, payment systems

Memory trick: HSM: Holds Secrets Magnificently!

More Security Engineering questions