City laptops use a TPM to protect device keys, while the certificate authority team evaluates an HSM for root and intermediate key operations. How do these technologies differ at a purpose level?
Select an answer to reveal the explanation.
Short Explanation
TPM is the laptop's built-in locked drawer for device keys; HSM is the bank vault appliance the CA uses for serious organizational key work. Same idea of hardware-backed protection, different jobs and scale.
Full Explanation
A Trusted Platform Module is typically integrated into a host to generate and protect keys bound to that platform. A Hardware Security Module is a dedicated, hardened appliance designed for high-assurance organizational key storage and cryptographic operations such as certificate authority signing. They are not interchangeable consumer password vaults, and neither role matches the distractors about Wi-Fi-only storage or phone-only use.