exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 41 discussion

Actual exam question from CompTIA's CAS-004
Question #: 41
Topic #: 1
[All CAS-004 Questions]

A company publishes several APIs for customers and is required to use keys to segregate customer data sets.
Which of the following would be BEST to use to store customer keys?

  • A. A trusted platform module
  • B. A hardware security module
  • C. A localized key store
  • D. A public key infrastructure
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 1 year, 10 months ago
Selected Answer: B
Of the options provided, the best choice for storing customer keys would be a hardware security module (HSM) or a secure key management service (KMS) or secret management service (SMS) provided by a cloud provider. A hardware security module (HSM) is a physical device that provides secure storage and management of cryptographic keys and other sensitive data. HSMs are often used in enterprise environments to protect against unauthorized access or tampering, and can be accessed through API calls or command-line tools. A trusted platform module (TPM) is a hw component that provides secure storage and management of cryptographic keys and other sensitive data, but it is primarily designed for use in personal computers and other consumer devices. It is not typically used for storing customer keys in an enterprise setting. A public key infrastructure (PKI) is a system for securely exchanging and managing digital certificates and keys, but it is not generally used to store customer keys. PKI is typically used to establish trust in online communications and transactions, and is not the best choice for storing customer keys in a segregated manner.
upvoted 11 times
...
FOURDUE
Highly Voted 1 year, 9 months ago
Selected Answer: B
A hardware security module (HSM) is a hardware unit that stores cryptographic keys to keep them private while ensuring they are available to those authorized to use them. The primary objective of HSM security is to control which individuals have access to an organization's digital security keys.
upvoted 5 times
...
Kabbath1986
Most Recent 9 months, 1 week ago
Selected Answer: D
I believe B is often included in PKI deployments. PKI is a broader concept
upvoted 2 times
...
BiteSize
1 year, 3 months ago
Selected Answer: B
Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 3 times
...
AnnoyingIAGuy
1 year, 9 months ago
Selected Answer: B
I would go with B
upvoted 4 times
...
ryanzou
2 years ago
Selected Answer: B
B is the most secure one.
upvoted 4 times
...
[Removed]
2 years ago
Selected Answer: B
The best would be an HSM because we are talking about API: HSMs use APIs and can support automated workflows and builds. They can also help meet FIPS compliance and generally offer a higher rating than tokens. Traditionally, HSMs are physical appliances located on-premises, requiring internal resources to manage and ensure baseline requirements and SLAs are met https://www.globalsign.com/en/blog/cryptographic-key-management-and-storage-best-practice
upvoted 4 times
...
examtaker135
2 years ago
The key word in this question is "BEST". Answer "D" could work but is not the best answer, so answer "B - HSM" works the best.
upvoted 1 times
...
ccryptix
2 years ago
Selected Answer: B
The reference given is for Android. If you want the BEST way, its B
upvoted 2 times
...
Scor65
2 years, 1 month ago
Selected Answer: B
Which would be BEST? D- OK but B is the Best and expensive to implement
upvoted 2 times
...
adamwella
2 years, 1 month ago
Selected Answer: B
APIs. HSMs support a range of application programming interfaces (APIs) that enable application integration and the development of custom applications, including the Public-Key Cryptography Standard and Cryptography API Next Generation.
upvoted 3 times
...
bangz23
2 years, 2 months ago
Selected Answer: D
D all day
upvoted 2 times
joinedatthehop
1 year, 1 month ago
PKI (Public Key Infrastructure) encrypts data and relies on public and private keys to encrypt that data.
upvoted 1 times
...
...
EZPASS
2 years, 3 months ago
I'm also leaning towards B. Anyone else? A hardware security module (HSM) is a physical computing device that safeguards and manages digital keys, performs encryption and decryption functions for digital signatures, strong authentication and other cryptographic functions.
upvoted 2 times
...
Dassler
2 years, 3 months ago
Isn't B "HSM" specifically designed to store cryptografic keys?
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago