Correct Answer: B
The correct answer is B. To provide secure key management.
The primary objective of hardware-based encryption in a banking system is to protect cryptographic keys and perform cryptographic operations in a secure, tamper-resistant environment. Banking systems commonly use hardware security modules, or HSMs, to protect keys used for payment processing, PIN handling, authentication, transaction signing, and encryption.
ISACA states that HSMs are widely recognized as one of the most secure ways to manage encryption and that organizations need HSMs for robust key management across the key life cycle, including generation, issuance, revocation, and rotation. ISACA also notes that cryptographic infrastructures are commonly built around FIPS-validated HSMs to provide a high level of security for encryption keys.
Option A is not the best answer because hardware-based encryption may make some key-management activities more controlled and centralized, but it does not necessarily simplify the process. In fact, HSMs can introduce operational complexity.
Option C is not the best answer because hardware encryption may improve cryptographic processing performance in some cases, but efficiency is not the primary reason for using it in a banking environment.
Option D is not the best answer because hardware-based encryption does not primarily exist to increase key length. Key length is determined by the encryption algorithm and security requirements, not simply by whether encryption is hardware-based.
This question maps to Protection of Information Assets because the CISA Exam Content Outline includes data encryption and public key infrastructure under Domain 5.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA guidance on HSMs, encryption, and key management.