ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 499 - CAS-004 discussion

Report
Export

A mobile device hardware manufacturer receives the following requirements from a company that wants to produce and sell a new mobile platform:

*The platform should store biometric data.

*The platform should prevent unapproved firmware from being loaded.

* A tamper-resistant, hardware-based counter should track if unapproved firmware was loaded.

Which of the following should the hardware manufacturer implement? (Select three).

A.
ASLR
Answers
A.
ASLR
B.
NX
Answers
B.
NX
C.
eFuse
Answers
C.
eFuse
D.
SED
Answers
D.
SED
E.
SELinux
Answers
E.
SELinux
F.
Secure boot
Answers
F.
Secure boot
G.
Shell restriction
Answers
G.
Shell restriction
H.
Secure enclave
Answers
H.
Secure enclave
Suggested answer: C, F, H

Explanation:

To meet the mobile platform security requirements, the manufacturer should implement the following technologies:

eFuse: This hardware feature helps track and prevent unauthorized firmware by physically 'blowing' fuses to record events, such as firmware tampering, making it impossible to revert to older, unapproved firmware.

Secure boot: This ensures that only trusted and authorized firmware can be loaded during the boot process, preventing malicious or unauthorized software from running.

Secure enclave: A secure enclave is used to store sensitive information like biometric data in a hardware-isolated environment, protecting it from tampering or unauthorized access.

These three solutions provide the tamper resistance, secure firmware validation, and protection of sensitive data required for the platform. CASP+ emphasizes the use of hardware-based security features for protecting sensitive information and enforcing secure boot processes in embedded and mobile systems.

CASP+ CAS-004 Exam Objectives: Domain 3.0 -- Enterprise Security Architecture (Secure Hardware and Firmware Protection)

CompTIA CASP+ Study Guide: Hardware Security Features (eFuse, Secure Boot, Secure Enclave)

asked 02/10/2024
han wu
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first