nerdexam
CompTIA

SY0-501 · Question #395

A security architect has convened a meeting to discuss an organization's key management policy. The organization has a reliable internal key management system, and some argue that it would be best…

The correct answer is C. risk benefits analysis results to make a determination. The organization should make its key management system decision based on a thorough risk-benefit analysis, rather than defaulting to an existing system or solely considering cost savings.

Submitted by ahmad_uae· Mar 4, 2026Security program management and oversight

Question

A security architect has convened a meeting to discuss an organization's key management policy. The organization has a reliable internal key management system, and some argue that it would be best to manage the cryptographic keys internally as opposed to using a solution from a third party. The company should use:

Options

  • Athe current internal key management system.
  • Ba third-party key management system that will reduce operating costs.
  • Crisk benefits analysis results to make a determination.
  • Da software solution including secure key escrow capabilities.

How the community answered

(45 responses)
  • A
    13% (6)
  • B
    7% (3)
  • C
    78% (35)
  • D
    2% (1)

Why each option

The organization should make its key management system decision based on a thorough risk-benefit analysis, rather than defaulting to an existing system or solely considering cost savings.

Athe current internal key management system.

Simply continuing with the current internal key management system without evaluating alternatives or current security posture might lead to missed opportunities for improved security or efficiency, or expose the organization to unaddressed risks.

Ba third-party key management system that will reduce operating costs.

While cost reduction is a factor, making a critical security decision solely on the basis of reducing operating costs, without a broader assessment of security, reliability, and strategic alignment, is an incomplete and potentially risky approach.

Crisk benefits analysis results to make a determination.Correct

When evaluating critical security infrastructure like a key management system, a comprehensive approach is essential. A risk-benefit analysis systematically evaluates the potential security risks, operational benefits, compliance implications, and costs associated with both internal and third-party solutions. This data-driven methodology ensures that the final decision aligns with the organization's overall risk appetite, security posture, and business objectives, providing a defensible rationale for the chosen key management strategy.

Da software solution including secure key escrow capabilities.

Key escrow capabilities are a specific feature of a key management system, but this choice does not provide a methodology for deciding between fundamental key management strategies (internal vs. third-party) or address the broader security and operational context.

Concept tested: Strategic security decision-making through risk-benefit analysis

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-30r1.pdf

Topics

#key management#cryptography#risk analysis#third-party risk

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice