CISA Protection of Information Assets Practice Question
An IS auditor is examining how a retail bank protects stored cardholder data. The bank encrypts the primary account number in its customer database using AES-256, but the auditor learns that the encryption keys are stored in a configuration file on the same database server, readable by the database administrator account. Which of the following is the MOST appropriate conclusion?
⚠ Common exam trap
The trap here is treating a long AES key length as proof of protection, when the real failure is that the key is stored with the data it is meant to protect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The encryption is ineffective for protecting confidentiality because the key is exposed wherever the data is exposed.
Strong encryption depends on keeping the key outside the reach of anyone who can access the ciphertext. When the key file sits on the database server and is readable by the database administrator, the separation of duties that gives encryption its value disappears, and a single compromised account yields both data and key. The auditor should conclude that confidentiality protection is defeated and recommend a dedicated key-management capability such as a hardware security module.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The finding is acceptable provided the database administrator's activity is logged and reviewed monthly.
Why it's wrong here
Logging and review are detective controls that may support an investigation after a breach, but they do not prevent the administrator from copying the key and the data together. Monthly review is far too slow to stop exfiltration, and a privileged user can often alter or disable logging. Detection cannot substitute for the preventive separation that proper key management requires.
- ✓
The encryption is ineffective for protecting confidentiality because the key is exposed wherever the data is exposed.
Why this is correct
Encryption only protects data when the key is held separately from the ciphertext. Storing the key in a file readable by the same administrator who can already query the database removes the separation, so anyone who compromises that account obtains both the data and the means to decrypt it. The control provides no meaningful additional confidentiality against that threat, which is the auditor's central concern.
- ✗
The bank should migrate the keys to a hardware security module but may continue storing them with the database until the migration completes.
Why it's wrong here
A hardware security module is the right long-term destination, but the interim exposure is precisely the risk being reported. Advising continued co-location of keys and data, even temporarily, leaves cardholder data decryptable by the same account that accesses the database. An auditor should recommend immediate compensating controls and accelerated migration rather than endorsing an indefinite period of exposure.
- ✗
The encryption remains effective because AES-256 is computationally infeasible to break by brute force.
Why it's wrong here
Algorithm strength is irrelevant when the key is available in plaintext beside the data. An attacker or rogue administrator does not need to break AES-256; they simply read the configuration file and decrypt normally. Citing key length confuses cryptographic strength with key-management practice, and would lead the auditor to accept a control that fails against the most likely threat.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.