exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 443 discussion

Actual exam question from CompTIA's CAS-004
Question #: 443
Topic #: 1
[All CAS-004 Questions]

Which of the following provides the best solution for organizations that want to securely back up the MFA seeds for its employees in a central, offline location with minimal management overhead?

  • A. Key escrow service
  • B. Secrets management
  • C. Encrypted database
  • D. Hardware security module
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
3 weeks, 5 days ago
Selected Answer: A
The best solution for securely backing up Multi-Factor Authentication (MFA) seeds for employees in a central, offline location with minimal management overhead is: A. Key escrow service. Key escrow service is designed to securely store and manage cryptographic keys, including MFA seeds. The "escrow" part refers to a trusted third party that holds the keys, which can be recovered if needed, ensuring secure backup of MFA seeds. This type of service is typically used for situations where keys must be stored in a way that they can be accessed under specific conditions but otherwise remain protected. NOT D. Hardware security module (HSM): While an HSM is excellent for securely generating and storing cryptographic keys, it is generally used for real-time operations, not necessarily for centralizing offline backups of MFA seeds. AND NOT C. Encrypted database: An encrypted database can be used for storing various types of sensitive data, but it requires ongoing management and doesn't inherently provide the offline storage feature or the level of protection specific to MFA seed backup.
upvoted 1 times
...
grelaman
3 months, 1 week ago
Selected Answer: C
The organization needs a secure, central, and offline solution to back up Multi-Factor Authentication (MFA) seeds with minimal management overhead. MFA seeds are sensitive pieces of information used to generate one-time passwords for authentication purposes. Storing them securely is critical to prevent unauthorized access, which could compromise the entire authentication system. By using an encrypted database, the organization can securely store the MFA seeds in a central, offline location with minimal ongoing management requirements. Why not D: An HSM is a physical device that manages digital keys for strong authentication and provides cryptographic processing. SMs are expensive to procure and maintain, which might not be justifiable for simply backing up MFA seeds. HSMs are better suited for high-security environments where cryptographic operations are performed frequently, not just for storage.
upvoted 1 times
grelaman
2 months, 1 week ago
Changing to D cause Setting up and maintaining an encrypted database requires specialized knowledge to ensure it's configured securely. Regular database maintenance, including backups, patches, and security audits, can significantly increase management efforts-
upvoted 1 times
...
...
ChopSNap
5 months, 4 weeks ago
Selected Answer: D
D. Hardware security module (HSM): HSMs are designed to securely manage and protect cryptographic keys and other sensitive information like MFA seeds, offering a high level of security in an offline environment with minimal management overhead.
upvoted 2 times
...
23169fd
6 months ago
Selected Answer: D
An HSM provides a highly secure method for storing and managing cryptographic keys and other sensitive data, including MFA seeds. HSMs are designed to be tamper-resistant and are capable of securely generating, storing, and backing up cryptographic keys in an offline environment. Once configured, HSMs require minimal management overhead and provide robust security features, including physical security, to protect the stored data.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago