Study. uk . com
  1. Home
  2. All questions
  3. Question 248

CompTIA Security+ study material · question 248 of 611

Why does NIST suggest storing a verifier's secret key in a hardware-protected area such as a TPM or trusted execution environment?

  1. To speed up hash verification
  2. So a compromised operating system still cannot read it
  3. To allow the key to be exported for backup
  4. To satisfy records retention requirements
Show the answer

Answer: B. So a compromised operating system still cannot read it

Isolation from the host means brute-force attacks on stolen hashes stay impractical as long as the key stays secret.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.1.2 Verifier Requirements

Challenge yourself on this topic → Study as cards