ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard

An organization is implementing a Trusted Platform Module (TPM) in its new laptop fleet. Beyond secure boot, which specific security capability does the TPM provide that helps ensure the integrity of the operating system and applications loaded after the initial boot process, particularly against persistent malware or rootkits?

  1. AMemory protection mechanisms for isolating application processes.
  2. BHardware-based encryption acceleration for disk encryption.
  3. CRemote attestation, allowing a trusted third party to verify the system's integrity state.
  4. DGeneration and secure storage of cryptographic keys.
Show answer & explanation

Correct answer: C. Remote attestation, allowing a trusted third party to verify the system's integrity state.

While TPMs provide secure key storage (B) and aid in encryption, and secure boot (initial boot integrity), remote attestation (C) is the capability that allows a trusted third party to verify the entire system's integrity state, including the operating system and application layers. The TPM creates a unique 'report' of the system's configuration and software measurements, which can be sent to a remote verifier to confirm that the system has not been tampered with and is running a trusted configuration, thereby protecting against persistent malware.

Why the other options are wrong

  • A. Memory protection is typically a function of the CPU and OS, not the TPM directly.
  • B. TPM can assist with key management for disk encryption but doesn't primarily provide encryption acceleration itself; dedicated hardware or CPU instructions do.
  • D. Secure key generation and storage is a core function, but remote attestation specifically addresses the integrity verification of the running OS and applications for a third party.

Remote Attestation (TPM)

A TPM capability that allows a remote entity to cryptographically verify the integrity of a system's hardware and software configuration.

  • Uses Platform Configuration Registers (PCRs) to store measurements of boot components.
  • A trusted third party can verify these measurements to confirm system integrity.
  • Helps detect rootkits or unauthorized modifications to the OS or applications.

Memory trick: Attestation Assures All is Authentic.

More Security Architecture and Engineering questions