220-1101 exam dumps

220-1101 practice question 287 of 471

A+ Core 1. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1101 Question 287

Single answerHardware security module (HSM)

A small medical office is replacing an aging file server that stores encrypted patient records. Management wants the server's encryption keys protected in dedicated hardware so the keys are harder to extract if the operating system is compromised. The technician is asked to recommend the best solution that can securely generate, store, and use the keys without exposing them directly to the server. Which of the following should the technician recommend?

  1. A

    A hardware security module (HSM)

  2. B

    A standard USB flash drive used to store a copy of the keys

  3. C

    A RAID controller with battery-backed cache

  4. D

    A NAS device configured with a shared folder for certificates

Show answer and explanation

Correct answer: A

Explanation

The best answer is a hardware security module (HSM). In real-world environments, an HSM is used when organizations need strong protection for cryptographic keys, such as keys used for data encryption, digital signing, or certificate services. The key benefit in this scenario is that the HSM can generate and safeguard keys inside dedicated hardware and perform cryptographic functions without unnecessarily exposing private key material to the host system. This aligns with common security best practices for protecting sensitive data, especially in regulated environments such as healthcare. By contrast, a USB drive, RAID controller, or NAS may store data but do not provide the dedicated cryptographic protections of an HSM. This fits A+ Core 1 expectations around identifying appropriate hardware security devices and their practical use cases.

  • A. Correct.

    Correct. A hardware security module (HSM) is a dedicated device designed to generate, store, and protect cryptographic keys and perform sensitive cryptographic operations in hardware. In this scenario, it best matches the requirement to keep encryption keys protected even if the server OS is compromised. HSMs are used to reduce the risk of key theft by isolating key material from the general-purpose system.

  • B. Incorrect.

    Incorrect. A USB flash drive can hold files, including exported keys, but it does not provide the secure hardware-based key generation, tamper resistance, or controlled cryptographic operations expected from an HSM. Storing keys on removable media is also operationally risky and does not meet the requirement to use the keys without exposing them directly to the server.

  • C. Incorrect.

    Incorrect. A RAID controller improves storage performance and fault tolerance for disks, and battery-backed cache helps preserve unwritten data during power loss. However, it does not function as a cryptographic key protection device and does not securely generate or isolate encryption keys.

  • D. Incorrect.

    Incorrect. A NAS shared folder can store certificate or key files, but it is still general network storage rather than a dedicated cryptographic security device. Saving keys on a NAS may improve centralization, but it does not provide the hardware-isolated key protection and secure cryptographic processing that an HSM provides.

Timed practice exam

Take a 220-1101 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam