- Home
- All questions
- Question 248
CompTIA Security+ study material · question 248 of 611
Why does NIST suggest storing a verifier's secret key in a hardware-protected area such as a TPM or trusted execution environment?
Show the answer
Answer: B. So a compromised operating system still cannot read it
Isolation from the host means brute-force attacks on stolen hashes stay impractical as long as the key stays secret.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 3.1.1.2 Verifier Requirements