nerdexam
CompTIA

CAS-002 · Question #250

A security architect is designing a new infrastructure using both type 1 and type 2 virtual machines. In addition to the normal complement of security controls (e.g. antivirus, host hardening…

The correct answer is A. vTPM. A Trusted Platform Module (TPM) is a microchip designed to provide basic security-related functions, primarily involving encryption keys. The TPM is usually installed on the motherboard of a computer, and it communicates with the remainder of the system by using a hardware bus…

Technical Integration of Enterprise Components

Question

A security architect is designing a new infrastructure using both type 1 and type 2 virtual machines. In addition to the normal complement of security controls (e.g. antivirus, host hardening, HIPS/NIDS) the security architect needs to implement a mechanism to securely store cryptographic keys used to sign code and code modules on the VMs. Which of the following will meet this goal without requiring any hardware pass-through implementations?

Options

  • AvTPM
  • BHSM
  • CTPM
  • DINE

How the community answered

(58 responses)
  • A
    76% (44)
  • B
    9% (5)
  • C
    12% (7)
  • D
    3% (2)

Explanation

A Trusted Platform Module (TPM) is a microchip designed to provide basic security-related functions, primarily involving encryption keys. The TPM is usually installed on the motherboard of a computer, and it communicates with the remainder of the system by using a hardware bus. A vTPM is a virtual Trusted Platform Module. IBM extended the current TPM V1.2 command set with virtual TPM management commands that allow us to create and delete instances of TPMs. Each created instance of a TPM holds an association with a virtual machine (VM) throughout its lifetime on the platform.

Topics

#vTPM#virtualization security#cryptographic key storage#hypervisor

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice