Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?

⚠ Common exam trap

CISA often tests the distinction between privacy-compliance metadata (location, retention) and security or financial metadata (encryption algorithm, cost), tempting candidates to pick controls that sound important but are not inventory essentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The location (systems and physical) where PII is stored

Option B is correct because a data inventory must record where PII resides—both the systems (applications, databases, cloud services) and physical locations—so the organization can apply appropriate safeguards and respond to access, breach, or deletion requests under privacy regulations. Option D is correct because documenting the retention period for each type of PII ensures data is kept only as long as legally or operationally necessary and is securely disposed of when that period ends, which is a core privacy compliance requirement. Option A is not essential to the inventory itself; encryption algorithms are security controls recorded in system documentation, not identifying attributes of a data inventory. Option C is irrelevant to privacy compliance, as storage cost is a financial metric rather than a data-governance attribute. Option E is unnecessary and impractical, since the inventory should identify processing activities and roles, not list every individual employee who handles the data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The encryption algorithm used to protect the data

    Why it's wrong here

    Encryption algorithms are security controls applied to data, not inventory attributes; a privacy inventory records what personal data exists, its location, purpose and retention. It is tempting because encryption details matter for compliance evidence, but they belong in a control register rather than the data inventory itself.

  • ✓

    The location (systems and physical) where PII is stored

    Why this is correct

    Recording where PII resides, both in systems and physical premises, is essential because privacy obligations attach to every storage location. Without this, the institution cannot scope subject access requests, cross-border transfer restrictions or breach notification, leaving copies of personal data unaccounted for during compliance assessments.

  • ✗

    The cost of storing the data

    Why it's wrong here

    Storage cost is a financial metric, not a privacy attribute; an inventory must record what personal data is held, where, why and for how long. It is tempting because cost tracking is a legitimate FinOps concern, but it does not evidence lawful processing or support data subject requests.

  • ✓

    The retention period for each type of PII

    Why this is correct

    Specifying retention periods per PII category satisfies the storage-limitation principle: personal data must not be kept longer than necessary. The inventory then drives defensible disposal, so the institution can evidence that expired records are purged rather than retained indefinitely, which privacy regulators routinely examine.

  • ✗

    The names of all employees who process the data

    Why it's wrong here

    Naming every employee who processes data creates a personnel list, not a data inventory; the inventory records the data itself, its categories, location, purpose and retention. It is tempting because accountability matters under privacy rules, but access records belong in an access register, not the inventory.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.