CISA Protection of Information Assets Practice Question
An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?
⚠ Common exam trap
CISA often tests the distinction between privacy-compliance metadata (location, retention) and security or financial metadata (encryption algorithm, cost), tempting candidates to pick controls that sound important but are not inventory essentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The location (systems and physical) where PII is stored
Option B is correct because a data inventory must record where PII resides—both the systems (applications, databases, cloud services) and physical locations—so the organization can apply appropriate safeguards and respond to access, breach, or deletion requests under privacy regulations. Option D is correct because documenting the retention period for each type of PII ensures data is kept only as long as legally or operationally necessary and is securely disposed of when that period ends, which is a core privacy compliance requirement. Option A is not essential to the inventory itself; encryption algorithms are security controls recorded in system documentation, not identifying attributes of a data inventory. Option C is irrelevant to privacy compliance, as storage cost is a financial metric rather than a data-governance attribute. Option E is unnecessary and impractical, since the inventory should identify processing activities and roles, not list every individual employee who handles the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The encryption algorithm used to protect the data
Why it's wrong here
Encryption algorithms are security controls applied to data, not inventory attributes; a privacy inventory records what personal data exists, its location, purpose and retention. It is tempting because encryption details matter for compliance evidence, but they belong in a control register rather than the data inventory itself.
- ✓
The location (systems and physical) where PII is stored
Why this is correct
Recording where PII resides, both in systems and physical premises, is essential because privacy obligations attach to every storage location. Without this, the institution cannot scope subject access requests, cross-border transfer restrictions or breach notification, leaving copies of personal data unaccounted for during compliance assessments.
- ✗
The cost of storing the data
Why it's wrong here
Storage cost is a financial metric, not a privacy attribute; an inventory must record what personal data is held, where, why and for how long. It is tempting because cost tracking is a legitimate FinOps concern, but it does not evidence lawful processing or support data subject requests.
- ✓
The retention period for each type of PII
Why this is correct
Specifying retention periods per PII category satisfies the storage-limitation principle: personal data must not be kept longer than necessary. The inventory then drives defensible disposal, so the institution can evidence that expired records are purged rather than retained indefinitely, which privacy regulators routinely examine.
- ✗
The names of all employees who process the data
Why it's wrong here
Naming every employee who processes data creates a personnel list, not a data inventory; the inventory records the data itself, its categories, location, purpose and retention. It is tempting because accountability matters under privacy rules, but access records belong in an access register, not the inventory.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.