Topic 04 Practice Test 1 covers Cryptography and PKI for CompTIA Security+ SY0-701 and maps to objective 1.4: Explain the importance of using appropriate cryptographic solutions. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
A review during a cryptographic architecture and PKI design review identifies two gaps. One requires technique that deliberately increases the computational cost of deriving a key from a password. The other requires centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation. Which TWO options should be included in the remediation plan? Choose TWO.
- Certificate signing request (CSR)
- Asymmetric encryption
- Key management system
- Key stretching
- Public key infrastructure
Correct Answers: C, D
Correct Answers
Answer C is correct because Key management system means a centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation. This option satisfies a specific requirement in the stem; Public key infrastructure serves the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates and therefore is not interchangeable with it.
Answer D is correct because Key stretching means a technique that deliberately increases the computational cost of deriving a key from a password. The fixed-count item needs this function in the answer set. Public key infrastructure covers the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates, a different requirement.
Incorrect Answers
Answer A is incorrect because Certificate signing request (CSR) means a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance. The scenario calls for Key stretching, Key management system. Selecting this option would leave one of those required functions uncovered.
Answer B is incorrect because Asymmetric encryption means cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange. The fixed-count answer set is Key stretching, Key management system; this option does not fill one of those named functions.
Answer E is incorrect because Public key infrastructure means the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates. The question requires exactly 2 selections: Key stretching, Key management system. This option falls outside that required set.
Question 2
Which request containing identifying information and a public key is submitted to a certificate authority for certificate issuance?
- Key escrow
- Full-disk encryption
- Online Certificate Status Protocol (OCSP)
- Certificate signing request (CSR)
Correct Answer: D
Correct Answer
Answer D is correct because Certificate signing request (CSR) means a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance. This is the precise fit for the scenario. Full-disk encryption serves the different purpose of encryption that protects an entire storage device so data remains unreadable without authorized unlocking.
Incorrect Answers
Answer A is incorrect because Key escrow refers to controlled storage of cryptographic keys so authorized recovery is possible under defined circumstances. The question is not asking for this function. It is testing a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance, so Certificate signing request (CSR) is the stronger fit.
Answer B is incorrect because Full-disk encryption refers to encryption that protects an entire storage device so data remains unreadable without authorized unlocking. That concept can be valid in another scenario, but this question is testing a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance; Certificate signing request (CSR) therefore fits the requirement more directly.
Answer C is incorrect because Online Certificate Status Protocol (OCSP) refers to a protocol used to query the current revocation status of a specific certificate. That concept can be valid in another scenario, but this question is testing a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance; Certificate signing request (CSR) therefore fits the requirement more directly.
Question 3
Which protocol is used to query the current revocation status of a specific certificate?
- Certificate authority
- Trusted Platform Module (TPM)
- Online Certificate Status Protocol (OCSP)
- Steganography
Correct Answer: C
Correct Answer
Answer C is correct because Online Certificate Status Protocol (OCSP) means a protocol used to query the current revocation status of a specific certificate. The deciding point is functional fit: this option covers the stated need, while Steganography addresses the concealment of information inside another apparently ordinary medium.
Incorrect Answers
Answer A is incorrect because Certificate authority refers to a trusted PKI entity that validates identity according to policy and digitally signs certificates. That concept can be valid in another scenario, but this question is testing a protocol used to query the current revocation status of a specific certificate; Online Certificate Status Protocol (OCSP) therefore fits the requirement more directly.
Answer B is incorrect because Trusted Platform Module (TPM) refers to a hardware-backed security component that can protect keys and attest to platform state. That concept can be valid in another scenario, but this question is testing a protocol used to query the current revocation status of a specific certificate; Online Certificate Status Protocol (OCSP) therefore fits the requirement more directly.
Answer D is incorrect because Steganography refers to the concealment of information inside another apparently ordinary medium. The key mismatch is functional: Online Certificate Status Protocol (OCSP) addresses a protocol used to query the current revocation status of a specific certificate, the need stated by the question.
Question 4
Which dedicated tamper-resistant device is used to generate, protect, and perform operations with high-value cryptographic keys?
- Key exchange
- Public key
- Digital signature
- Hardware security module (HSM)
Correct Answer: D
Correct Answer
Answer D is correct because Hardware security module (HSM) means a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys. That is the function the question is testing. Public key would instead be used for the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder.
Incorrect Answers
Answer A is incorrect because Key exchange refers to a method that lets parties establish or agree on cryptographic key material over an untrusted network. The question is not asking for this function. It is testing a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys, so Hardware security module (HSM) is the stronger fit.
Answer B is incorrect because Public key refers to the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder. That concept can be valid in another scenario, but this question is testing a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys; Hardware security module (HSM) therefore fits the requirement more directly.
Answer C is incorrect because Digital signature refers to a cryptographic value created with a private key and verified with the corresponding public key. This could be appropriate elsewhere, but the required function is a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys; that makes Hardware security module (HSM) the precise choice.
Question 5
Which term describes cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange?
- Asymmetric encryption
- Certificate authority
- Public key infrastructure
- Steganography
Correct Answer: A
Correct Answer
Answer A is correct because Asymmetric encryption means cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange. The deciding point is functional fit: this option covers the stated need, while Certificate authority addresses a trusted PKI entity that validates identity according to policy and digitally signs certificates.
Incorrect Answers
Answer B is incorrect because Certificate authority refers to a trusted PKI entity that validates identity according to policy and digitally signs certificates. The scenario instead requires cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange, which is why Asymmetric encryption is the better answer; this option serves the different function defined above.
Answer C is incorrect because Public key infrastructure refers to the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates. The scenario instead requires cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange, which is why Asymmetric encryption is the better answer; this option serves the different function defined above.
Answer D is incorrect because Steganography refers to the concealment of information inside another apparently ordinary medium. The scenario instead requires cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange, which is why Asymmetric encryption is the better answer; this option serves the different function defined above.
Question 6
A payment system replaces sensitive values with non-sensitive surrogates whose meaning depends on a protected mapping service. Which data-protection approach is being applied?
- Data masking
- Online Certificate Status Protocol (OCSP)
- Symmetric encryption
- Tokenization
Correct Answer: D
Correct Answer
Answer D is correct because Tokenization means replacement of sensitive data with a non-sensitive surrogate token that has little or no exploitable value outside the tokenization system. This matches the requirement as written. Data masking can be valid in another context, but it is used for alteration or obscuring of sensitive values so users or systems see realistic but protected representations.
Incorrect Answers
Answer A is incorrect because Data masking refers to alteration or obscuring of sensitive values so users or systems see realistic but protected representations. The scenario instead requires replacement of sensitive data with a non-sensitive surrogate token that has little or no exploitable value outside the tokenization system, which is why Tokenization is the better answer; this option serves the different function defined above.
Answer B is incorrect because Online Certificate Status Protocol (OCSP) refers to a protocol used to query the current revocation status of a specific certificate. The key mismatch is functional: Tokenization addresses replacement of sensitive data with a non-sensitive surrogate token that has little or no exploitable value outside the tokenization system, the need stated by the question.
Answer C is incorrect because Symmetric encryption refers to encryption that uses the same secret key for encryption and decryption and is efficient for protecting large volumes of data. The concept is valid, but it does not match this stem. The required function is replacement of sensitive data with a non-sensitive surrogate token that has little or no exploitable value outside the tokenization system, which maps to Tokenization.
Question 7
Which hardware-backed security component can protect keys and attest to platform state?
- Online Certificate Status Protocol (OCSP)
- Trusted Platform Module (TPM)
- Public key
- Transport encryption
Correct Answer: B
Correct Answer
Answer B is correct because Trusted Platform Module (TPM) means a hardware-backed security component that can protect keys and attest to platform state. The deciding point is functional fit: this option covers the stated need, while Transport encryption addresses encryption applied to communications while data moves between endpoints.
Incorrect Answers
Answer A is incorrect because Online Certificate Status Protocol (OCSP) refers to a protocol used to query the current revocation status of a specific certificate. That concept can be valid in another scenario, but this question is testing a hardware-backed security component that can protect keys and attest to platform state; Trusted Platform Module (TPM) therefore fits the requirement more directly.
Answer C is incorrect because Public key refers to the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder. This could be appropriate elsewhere, but the required function is a hardware-backed security component that can protect keys and attest to platform state; that makes Trusted Platform Module (TPM) the precise choice.
Answer D is incorrect because Transport encryption refers to encryption applied to communications while data moves between endpoints. That concept can be valid in another scenario, but this question is testing a hardware-backed security component that can protect keys and attest to platform state; Trusted Platform Module (TPM) therefore fits the requirement more directly.
Question 8
To allow others to perform operations that do not reveal the private key, which security approach should be selected?
- Public key
- Transport encryption
- Secure enclave
- Data masking
Correct Answer: A
Correct Answer
Answer A is correct because Public key means the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder. That makes it the best answer here; Data masking addresses alteration or obscuring of sensitive values so users or systems see realistic but protected representations, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Transport encryption refers to encryption applied to communications while data moves between endpoints. That concept can be valid in another scenario, but this question is testing the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder; Public key therefore fits the requirement more directly.
Answer C is incorrect because Secure enclave refers to an isolated protected execution area used to keep sensitive code or cryptographic material separate from the normal operating environment. The scenario instead requires the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder, which is why Public key is the better answer; this option serves the different function defined above.
Answer D is incorrect because Data masking refers to alteration or obscuring of sensitive values so users or systems see realistic but protected representations. The question is not asking for this function. It is testing the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder, so Public key is the stronger fit.
Question 9
During a cryptographic architecture and PKI design review, the team has two independent requirements: (1) cryptographic value created with a private key and verified with the corresponding public key; and (2) secret half of an asymmetric key pair that must remain controlled by its owner. Which TWO choices best satisfy those requirements? Choose TWO.
- Full-disk encryption
- Private key
- Secure enclave
- Transport encryption
- Digital signature
Correct Answers: B, E
Correct Answers
Answer B is correct because Private key means the secret half of an asymmetric key pair that must remain controlled by its owner. This selection maps directly to one of the named needs. Full-disk encryption addresses encryption that protects an entire storage device so data remains unreadable without authorized unlocking, so it does not satisfy the same slot.
Answer E is correct because Digital signature means a cryptographic value created with a private key and verified with the corresponding public key. This selection maps directly to one of the named needs. Secure enclave addresses an isolated protected execution area used to keep sensitive code or cryptographic material separate from the normal operating environment, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Full-disk encryption means encryption that protects an entire storage device so data remains unreadable without authorized unlocking. The question requires exactly 2 selections: Private key, Digital signature. This option falls outside that required set.
Answer C is incorrect because Secure enclave means an isolated protected execution area used to keep sensitive code or cryptographic material separate from the normal operating environment. The question requires exactly 2 selections: Private key, Digital signature. This option falls outside that required set.
Answer D is incorrect because Transport encryption means encryption applied to communications while data moves between endpoints. Every answer slot must map to a stated requirement. The correct set is Private key, Digital signature, so this option cannot replace one of those selections.
Question 10
To let relying parties identify certificates that should no longer be trusted, which security approach should be selected?
- Hardware security module (HSM)
- Steganography
- Certificate revocation list (CRL)
- Hashing
Correct Answer: C
Correct Answer
Answer C is correct because Certificate revocation list (CRL) means a published list of certificates that a certificate authority has revoked before their scheduled expiration. This is the precise fit for the scenario. Hashing serves the different purpose of a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity.
Incorrect Answers
Answer A is incorrect because Hardware security module (HSM) refers to a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys. The concept is valid, but it does not match this stem. The required function is a published list of certificates that a certificate authority has revoked before their scheduled expiration, which maps to Certificate revocation list (CRL).
Answer B is incorrect because Steganography refers to the concealment of information inside another apparently ordinary medium. The question is not asking for this function. It is testing a published list of certificates that a certificate authority has revoked before their scheduled expiration, so Certificate revocation list (CRL) is the stronger fit.
Answer D is incorrect because Hashing refers to a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity. That concept can be valid in another scenario, but this question is testing a published list of certificates that a certificate authority has revoked before their scheduled expiration; Certificate revocation list (CRL) therefore fits the requirement more directly.
Question 11
Two requirements remain open in a cryptographic architecture and PKI design review: encryption that protects an entire storage device so data remains unreadable without authorized unlocking; alteration or obscuring of sensitive values so users or systems see realistic but protected representations. Which TWO options close those specific gaps? Choose TWO.
- Data masking
- Full-disk encryption
- Hashing
- Symmetric encryption
- Certificate revocation list (CRL)
Correct Answers: A, B
Correct Answers
Answer A is correct because Data masking means alteration or obscuring of sensitive values so users or systems see realistic but protected representations. One required function is exactly what this option provides. Certificate revocation list (CRL) may be useful elsewhere, but it is used for a published list of certificates that a certificate authority has revoked before their scheduled expiration.
Answer B is correct because Full-disk encryption means encryption that protects an entire storage device so data remains unreadable without authorized unlocking. One required function is exactly what this option provides. Symmetric encryption may be useful elsewhere, but it is used for encryption that uses the same secret key for encryption and decryption and is efficient for protecting large volumes of data.
Incorrect Answers
Answer C is incorrect because Hashing means a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity. The required choices are Full-disk encryption, Data masking. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer D is incorrect because Symmetric encryption means encryption that uses the same secret key for encryption and decryption and is efficient for protecting large volumes of data. The question requires exactly 2 selections: Full-disk encryption, Data masking. This option falls outside that required set.
Answer E is incorrect because Certificate revocation list (CRL) means a published list of certificates that a certificate authority has revoked before their scheduled expiration. Every answer slot must map to a stated requirement. The correct set is Full-disk encryption, Data masking, so this option cannot replace one of those selections.
Question 12
An architect working on a cryptographic architecture and PKI design review needs one capability that provides technique that deliberately increases the computational cost of deriving a key from a password and another that provides dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys. Which TWO selections are the best match? Choose TWO.
- Key management system
- Hardware security module (HSM)
- Public key infrastructure
- Trusted Platform Module (TPM)
- Key stretching
Correct Answers: B, E
Correct Answers
Answer B is correct because Hardware security module (HSM) means a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys. This selection maps directly to one of the named needs. Key management system addresses a centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation, so it does not satisfy the same slot.
Answer E is correct because Key stretching means a technique that deliberately increases the computational cost of deriving a key from a password. This option satisfies a specific requirement in the stem; Public key infrastructure serves the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Key management system means a centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation. The fixed-count answer set is Key stretching, Hardware security module (HSM); this option does not fill one of those named functions.
Answer C is incorrect because Public key infrastructure means the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates. The fixed-count answer set is Key stretching, Hardware security module (HSM); this option does not fill one of those named functions.
Answer D is incorrect because Trusted Platform Module (TPM) means a hardware-backed security component that can protect keys and attest to platform state. The question requires exactly 2 selections: Key stretching, Hardware security module (HSM). This option falls outside that required set.
Question 13
To cover many sibling subdomains with one certificate when policy permits, which security approach should be selected?
- Key stretching
- Wildcard certificate
- Key exchange
- Online Certificate Status Protocol (OCSP)
Correct Answer: B
Correct Answer
Answer B is correct because Wildcard certificate means a certificate that can secure multiple hostnames at one domain level through a wildcard name such as *.example.com. The requirement maps directly to this function, whereas Key stretching is aimed at a technique that deliberately increases the computational cost of deriving a key from a password.
Incorrect Answers
Answer A is incorrect because Key stretching refers to a technique that deliberately increases the computational cost of deriving a key from a password. That concept can be valid in another scenario, but this question is testing a certificate that can secure multiple hostnames at one domain level through a wildcard name such as *.example.com; Wildcard certificate therefore fits the requirement more directly.
Answer C is incorrect because Key exchange refers to a method that lets parties establish or agree on cryptographic key material over an untrusted network. The question is not asking for this function. It is testing a certificate that can secure multiple hostnames at one domain level through a wildcard name such as *.example.com, so Wildcard certificate is the stronger fit.
Answer D is incorrect because Online Certificate Status Protocol (OCSP) refers to a protocol used to query the current revocation status of a specific certificate. That concept can be valid in another scenario, but this question is testing a certificate that can secure multiple hostnames at one domain level through a wildcard name such as *.example.com; Wildcard certificate therefore fits the requirement more directly.
Question 14
A security plan created during a cryptographic architecture and PKI design review must provide dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys, alteration or obscuring of sensitive values so users or systems see realistic but protected representations, and request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance. Which THREE options should be selected? Choose THREE.
- Data masking
- Trusted Platform Module (TPM)
- Certificate signing request (CSR)
- Public key
- Key escrow
- Hardware security module (HSM)
Correct Answers: A, C, F
Correct Answers
Answer A is correct because Data masking means alteration or obscuring of sensitive values so users or systems see realistic but protected representations. One required function is exactly what this option provides. Trusted Platform Module (TPM) may be useful elsewhere, but it is used for a hardware-backed security component that can protect keys and attest to platform state.
Answer C is correct because Certificate signing request (CSR) means a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance. This selection maps directly to one of the named needs. Key escrow addresses controlled storage of cryptographic keys so authorized recovery is possible under defined circumstances, so it does not satisfy the same slot.
Answer F is correct because Hardware security module (HSM) means a dedicated tamper-resistant device used to generate, protect, and perform operations with high-value cryptographic keys. This option satisfies a specific requirement in the stem; Key escrow serves controlled storage of cryptographic keys so authorized recovery is possible under defined circumstances and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Trusted Platform Module (TPM) means a hardware-backed security component that can protect keys and attest to platform state. The question requires exactly 3 selections: Hardware security module (HSM), Certificate signing request (CSR), Data masking. This option falls outside that required set.
Answer D is incorrect because Public key means the shareable half of an asymmetric key pair, commonly used to verify signatures or encrypt material for the private-key holder. The required choices are Hardware security module (HSM), Certificate signing request (CSR), Data masking. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Key escrow means controlled storage of cryptographic keys so authorized recovery is possible under defined circumstances. The required choices are Hardware security module (HSM), Certificate signing request (CSR), Data masking. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 15
Which technique deliberately increases the computational cost of deriving a key from a password?
- Online Certificate Status Protocol (OCSP)
- Key stretching
- Steganography
- Key exchange
Correct Answer: B
Correct Answer
Answer B is correct because Key stretching means a technique that deliberately increases the computational cost of deriving a key from a password. This is the precise fit for the scenario. Key exchange serves the different purpose of a method that lets parties establish or agree on cryptographic key material over an untrusted network.
Incorrect Answers
Answer A is incorrect because Online Certificate Status Protocol (OCSP) refers to a protocol used to query the current revocation status of a specific certificate. The concept is valid, but it does not match this stem. The required function is a technique that deliberately increases the computational cost of deriving a key from a password, which maps to Key stretching.
Answer C is incorrect because Steganography refers to the concealment of information inside another apparently ordinary medium. The concept is valid, but it does not match this stem. The required function is a technique that deliberately increases the computational cost of deriving a key from a password, which maps to Key stretching.
Answer D is incorrect because Key exchange refers to a method that lets parties establish or agree on cryptographic key material over an untrusted network. The concept is valid, but it does not match this stem. The required function is a technique that deliberately increases the computational cost of deriving a key from a password, which maps to Key stretching.
Question 16
Which secret half of an asymmetric key pair must remain controlled by its owner?
- Tokenization
- Key management system
- Private key
- Online Certificate Status Protocol (OCSP)
Correct Answer: C
Correct Answer
Answer C is correct because Private key means the secret half of an asymmetric key pair that must remain controlled by its owner. That makes it the best answer here; Key management system addresses a centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Tokenization refers to replacement of sensitive data with a non-sensitive surrogate token that has little or no exploitable value outside the tokenization system. The scenario instead requires the secret half of an asymmetric key pair that must remain controlled by its owner, which is why Private key is the better answer; this option serves the different function defined above.
Answer B is incorrect because Key management system refers to a centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation. The key mismatch is functional: Private key addresses the secret half of an asymmetric key pair that must remain controlled by its owner, the need stated by the question.
Answer D is incorrect because Online Certificate Status Protocol (OCSP) refers to a protocol used to query the current revocation status of a specific certificate. The scenario instead requires the secret half of an asymmetric key pair that must remain controlled by its owner, which is why Private key is the better answer; this option serves the different function defined above.
Question 17
A review during a cryptographic architecture and PKI design review identifies two gaps. One requires encryption that uses the same secret key for encryption and decryption and is efficient for protecting large volumes of data. The other requires alteration or obscuring of sensitive values so users or systems see realistic but protected representations. Which TWO options should be included in the remediation plan? Choose TWO.
- Certificate signing request (CSR)
- Trusted Platform Module (TPM)
- Private key
- Symmetric encryption
- Data masking
Correct Answers: D, E
Correct Answers
Answer D is correct because Symmetric encryption means encryption that uses the same secret key for encryption and decryption and is efficient for protecting large volumes of data. One required function is exactly what this option provides. Trusted Platform Module (TPM) may be useful elsewhere, but it is used for a hardware-backed security component that can protect keys and attest to platform state.
Answer E is correct because Data masking means alteration or obscuring of sensitive values so users or systems see realistic but protected representations. This option satisfies a specific requirement in the stem; Trusted Platform Module (TPM) serves a hardware-backed security component that can protect keys and attest to platform state and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Certificate signing request (CSR) means a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance. The question requires exactly 2 selections: Data masking, Symmetric encryption. This option falls outside that required set.
Answer B is incorrect because Trusted Platform Module (TPM) means a hardware-backed security component that can protect keys and attest to platform state. The required choices are Data masking, Symmetric encryption. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Private key means the secret half of an asymmetric key pair that must remain controlled by its owner. The question requires exactly 2 selections: Data masking, Symmetric encryption. This option falls outside that required set.
Question 18
To protect data at rest on a lost or stolen endpoint, which security approach should be selected?
- Full-disk encryption
- Certificate signing request (CSR)
- Digital signature
- Key stretching
Correct Answer: A
Correct Answer
Answer A is correct because Full-disk encryption means encryption that protects an entire storage device so data remains unreadable without authorized unlocking. This is the precise fit for the scenario. Key stretching serves the different purpose of a technique that deliberately increases the computational cost of deriving a key from a password.
Incorrect Answers
Answer B is incorrect because Certificate signing request (CSR) refers to a request containing identifying information and a public key that is submitted to a certificate authority for certificate issuance. The key mismatch is functional: Full-disk encryption addresses encryption that protects an entire storage device so data remains unreadable without authorized unlocking, the need stated by the question.
Answer C is incorrect because Digital signature refers to a cryptographic value created with a private key and verified with the corresponding public key. The concept is valid, but it does not match this stem. The required function is encryption that protects an entire storage device so data remains unreadable without authorized unlocking, which maps to Full-disk encryption.
Answer D is incorrect because Key stretching refers to a technique that deliberately increases the computational cost of deriving a key from a password. That concept can be valid in another scenario, but this question is testing encryption that protects an entire storage device so data remains unreadable without authorized unlocking; Full-disk encryption therefore fits the requirement more directly.
Question 19
Which one-way transformation produces a fixed-length digest and is commonly used to verify integrity?
- Key escrow
- Hashing
- Public key infrastructure
- Trusted Platform Module (TPM)
Correct Answer: B
Correct Answer
Answer B is correct because Hashing means a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity. This is the precise fit for the scenario. Key escrow serves the different purpose of controlled storage of cryptographic keys so authorized recovery is possible under defined circumstances.
Incorrect Answers
Answer A is incorrect because Key escrow refers to controlled storage of cryptographic keys so authorized recovery is possible under defined circumstances. The key mismatch is functional: Hashing addresses a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity, the need stated by the question.
Answer C is incorrect because Public key infrastructure refers to the people, policies, processes, and technology used to issue, validate, manage, and revoke digital certificates. This could be appropriate elsewhere, but the required function is a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity; that makes Hashing the precise choice.
Answer D is incorrect because Trusted Platform Module (TPM) refers to a hardware-backed security component that can protect keys and attest to platform state. The concept is valid, but it does not match this stem. The required function is a one-way transformation that produces a fixed-length digest and is commonly used to verify integrity, which maps to Hashing.
Question 20
To allow testing, analytics, or support work without exposing full sensitive data, which security approach should be selected?
- Asymmetric encryption
- Key management system
- Data masking
- Root of trust
Correct Answer: C
Correct Answer
Answer C is correct because Data masking means alteration or obscuring of sensitive values so users or systems see realistic but protected representations. The deciding point is functional fit: this option covers the stated need, while Asymmetric encryption addresses cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange.
Incorrect Answers
Answer A is incorrect because Asymmetric encryption refers to cryptography that uses mathematically related public and private keys for functions such as encryption, signatures, and key exchange. The scenario instead requires alteration or obscuring of sensitive values so users or systems see realistic but protected representations, which is why Data masking is the better answer; this option serves the different function defined above.
Answer B is incorrect because Key management system refers to a centralized service that controls the lifecycle of cryptographic keys, including creation, storage, rotation, and revocation. That concept can be valid in another scenario, but this question is testing alteration or obscuring of sensitive values so users or systems see realistic but protected representations; Data masking therefore fits the requirement more directly.
Answer D is incorrect because Root of trust refers to a highly trusted foundation, such as a root certificate or hardware anchor, from which other trust decisions are derived. That concept can be valid in another scenario, but this question is testing alteration or obscuring of sensitive values so users or systems see realistic but protected representations; Data masking therefore fits the requirement more directly.