Security+ Lesson

Cryptographic Support Tools for Security+

Last updated: 6/10/2026

Short answer

Cryptography depends on protecting keys. Strong algorithms do not help if private keys, disk encryption keys, signing keys, or application programming interface (API) encryption keys are exposed. TPMs, HSMs, key management systems, and secure enclaves support cryptography by reducing where keys appear, controlling key use, or isolating sensitive operations.

Why it appears on the exam

SY0-701 1.4: Recognize TPMs, HSMs, key management systems, and secure enclaves and explain when each supports key protection or trusted execution.

Key concepts

Concept 1

How Cryptographic Support Tools works

Cryptography depends on protecting keys. Strong algorithms do not help if private keys, disk encryption keys, signing keys, or API encryption keys are exposed. TPMs, HSMs, key management systems, and secure enclaves support cryptography by reducing where keys appear, controlling key use, or isolating sensitive operations.

Example

A laptop stores disk encryption key material in hardware tied to the device. Trusted Platform Module (TPM) is the best match.

Concept 2

Common confusion

Learners often treat TPM, hardware security module (HSM), KMS, and secure enclave as interchangeable vaults. The shortest correction is: TPM is local device hardware trust, HSM is dedicated tamper-resistant key hardware, KMS is key lifecycle management, and secure enclave is isolated trusted execution.

Example

A certificate authority needs to protect its signing private key in tamper-resistant hardware. HSM is the best match.

Concept 3

What to recognize

Choose TPM, HSM, KMS, or secure enclave from a short scenario; Distinguish hardware-backed key protection from key lifecycle management; Recognize that HSMs are used for high-value or centralized key protection; Recognize that secure enclaves protect sensitive processing from the rest of the system.

Example

A cloud application needs key rotation, access policy, audit logs, and centralized key lifecycle control. KMS is the best match.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: A laptop stores disk encryption key material in hardware tied to the device. Which answer matches it?

Q2.A Security+ scenario centers on Cryptographic Support Tools. Which answer is the closest lesson match?

Q3.A Security+ scenario about Cryptographic Support Tools looks similar to a nearby topic. What should you do before choosing an answer?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8