SY0-301 · Question #4
Which of the following would be used when a higher level of security is desired for encryption key storage?
The correct answer is D. TPM. A Trusted Platform Module (TPM) is a dedicated hardware chip embedded in a device that provides secure key storage and cryptographic operations at the hardware level. It offers a higher security assurance level than software-based key stores.
Question
Which of the following would be used when a higher level of security is desired for encryption key storage?
Options
- ATACACS+
- BL2TP
- CLDAP
- DTPM
How the community answered
(49 responses)- A2% (1)
- C4% (2)
- D94% (46)
Why each option
A Trusted Platform Module (TPM) is a dedicated hardware chip embedded in a device that provides secure key storage and cryptographic operations at the hardware level. It offers a higher security assurance level than software-based key stores.
TACACS+ is a Cisco-proprietary authentication, authorization, and accounting protocol used for device administration access control, not for encryption key storage.
L2TP (Layer 2 Tunneling Protocol) is a VPN tunneling protocol used to create network tunnels and does not provide any encryption key storage functionality.
LDAP (Lightweight Directory Access Protocol) is a protocol for querying and modifying directory services like Active Directory and does not store or protect encryption keys.
A TPM is a hardware-based security chip that securely stores encryption keys, certificates, and passwords in tamper-resistant hardware, bound to the specific device. Because keys are protected by hardware rather than software, it provides a higher assurance level and prevents key extraction even if the operating system is compromised.
Concept tested: TPM hardware-based encryption key storage
Source: https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/trusted-platform-module-overview
Topics
Community Discussion
No community discussion yet for this question.