nerdexam
CompTIA

SY0-301 · Question #4

Which of the following would be used when a higher level of security is desired for encryption key storage?

The correct answer is D. TPM. A Trusted Platform Module (TPM) is a dedicated hardware chip embedded in a device that provides secure key storage and cryptographic operations at the hardware level. It offers a higher security assurance level than software-based key stores.

General security concepts

Question

Which of the following would be used when a higher level of security is desired for encryption key storage?

Options

  • ATACACS+
  • BL2TP
  • CLDAP
  • DTPM

How the community answered

(49 responses)
  • A
    2% (1)
  • C
    4% (2)
  • D
    94% (46)

Why each option

A Trusted Platform Module (TPM) is a dedicated hardware chip embedded in a device that provides secure key storage and cryptographic operations at the hardware level. It offers a higher security assurance level than software-based key stores.

ATACACS+

TACACS+ is a Cisco-proprietary authentication, authorization, and accounting protocol used for device administration access control, not for encryption key storage.

BL2TP

L2TP (Layer 2 Tunneling Protocol) is a VPN tunneling protocol used to create network tunnels and does not provide any encryption key storage functionality.

CLDAP

LDAP (Lightweight Directory Access Protocol) is a protocol for querying and modifying directory services like Active Directory and does not store or protect encryption keys.

DTPMCorrect

A TPM is a hardware-based security chip that securely stores encryption keys, certificates, and passwords in tamper-resistant hardware, bound to the specific device. Because keys are protected by hardware rather than software, it provides a higher assurance level and prevents key extraction even if the operating system is compromised.

Concept tested: TPM hardware-based encryption key storage

Source: https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/trusted-platform-module-overview

Topics

#TPM#encryption key storage#hardware security#trusted platform module

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice