ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard

A cryptocurrency exchange platform is implementing a new system to manage user wallets and transaction keys. Due to the high value and sensitivity of these assets, the platform requires a solution that generates, stores, and manages cryptographic keys in a hardened, tamper-resistant hardware device. Which security architecture element is best suited for this purpose?

  1. ASoftware-based Key Management System (KMS)
  2. BIntrusion Prevention System (IPS)
  3. CVirtual Machine Monitor (VMM)
  4. DHardware Security Module (HSM)
Show answer & explanation

Correct answer: D. Hardware Security Module (HSM)

A Hardware Security Module (HSM) is a physical computing device that safeguards and manages digital keys, performs encryption and decryption functions, and provides a hardware root of trust. Its tamper-resistant design makes it ideal for securing high-value cryptographic keys like those used in cryptocurrency exchanges.

Why the other options are wrong

  • A. Software-based KMS lacks the tamper-resistance and hardware-backed security of an HSM.
  • B. An IPS detects and prevents network intrusions, unrelated to secure key management.
  • C. A VMM (hypervisor) manages virtual machines but doesn't provide hardened key management.

Hardware Security Module (HSM)

A physical computing device that safeguards and manages digital keys, performs encryption and decryption functions, and provides a hardware root of trust.

  • Offers a high level of security due to its tamper-resistant and tamper-evident design.
  • Used for protecting cryptographic keys, digital signatures, and certificate authorities.
  • Complies with industry standards like FIPS 140-2 for cryptographic modules.

Memory trick: HSM: The 'H'ardened 'S'ecurity 'M'achine for your most 'M'portant keys.

More Security Architecture and Engineering questions