Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?

⚠ Common exam trap

CISA often tests the misconception that any encryption satisfies the safe harbor, when the real trap is key management: storing keys with the data defeats encryption and is the most severe risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encryption keys are stored on the same server as the encrypted data.

HIPAA's encryption safe harbor only applies if ePHI is rendered unusable, unreadable, or indecipherable to unauthorized persons. If the encryption keys are stored on the same server as the encrypted data, an attacker who compromises that server obtains both the ciphertext and the keys, effectively defeating the encryption. This is the most significant risk because it nullifies the safe harbor protection entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Encryption keys are stored on the same server as the encrypted data.

    Why this is correct

    Storing keys alongside ciphertext collapses the two-party separation encryption depends on: anyone gaining server access obtains both data and keys, rendering encryption ineffective. This defeats HIPAA's safe harbour premise, which assumes keys remain protected and separate, so a single compromise exposes all protected health information.

  • ✗

    The encryption algorithm used is not FIPS 140-2 validated.

    Why it's wrong here

    A non-validated algorithm still encrypts ePHI, so the safe harbour's core requirement of rendering data unusable may be met; FIPS validation is a procurement and assurance standard, not the operative HIPAA test. It would be decisive where federal contracts or FedRAMP mandate validated cryptography.

  • ✗

    Encryption is not applied to all ePHI in transit.

    Why it's wrong here

    Leaving some ePHI unencrypted in transit means that data falls outside the safe harbour entirely, so a breach of it triggers notification duties. Partial coverage is tempting because encrypting the majority of traffic looks compliant, yet the safe harbour applies per record, not on average.

  • ✗

    The encryption key rotation policy is not documented.

    Why it's wrong here

    An undocumented key rotation policy is a documentation gap, not a technical failure of the encryption itself; HIPAA's safe harbour hinges on the data being rendered unusable, which undocumented rotation does not directly undermine. It would matter where governance evidence is required, such as an audit of key management procedures.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.