Courseiva
easyMultiple ChoiceObjective-mapped

CISA Practice Question: A company's security policy requires that all…

A company's security policy requires that all laptops have full disk encryption. During an audit, it is discovered that several laptops have encryption enabled but the recovery keys are stored on the local drive. What is the MOST significant risk?

⚠ Common exam trap

Candidates often confuse 'encryption enabled' with 'data protected' and pick Option B (unauthorized access) without recognizing that the recovery key on the local drive is the direct mechanism that enables that access, making Option C the root cause and most significant risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Recovery keys can be used to bypass encryption.

Storing recovery keys on the local drive defeats the purpose of full disk encryption (FDE). If an attacker gains physical access to the laptop, they can simply boot an alternate OS or mount the drive and read the recovery key file, then use it to unlock the encrypted volume. This bypasses the encryption entirely, making the data vulnerable to unauthorized access despite encryption being enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Performance degradation due to encryption overhead.

    Why it's wrong here

    Performance impact is minimal and not the main risk.

  • Unauthorized access to encrypted data.

    Why it's wrong here

    Encryption is working, but local keys allow bypass.

  • Recovery keys can be used to bypass encryption.

    Why this is correct

    Local storage of keys allows attackers to decrypt data easily.

  • Data corruption during encryption process.

    Why it's wrong here

    Encryption rarely causes corruption.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.