Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is examining how a retail bank protects stored cardholder data. The bank encrypts the primary account number in its customer database using AES-256, but the auditor learns that the encryption keys are stored in a configuration file on the same database server, readable by the database administrator account. Which of the following is the MOST appropriate conclusion?

⚠ Common exam trap

The trap here is treating a long AES key length as proof of protection, when the real failure is that the key is stored with the data it is meant to protect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The encryption is ineffective for protecting confidentiality because the key is exposed wherever the data is exposed.

Strong encryption depends on keeping the key outside the reach of anyone who can access the ciphertext. When the key file sits on the database server and is readable by the database administrator, the separation of duties that gives encryption its value disappears, and a single compromised account yields both data and key. The auditor should conclude that confidentiality protection is defeated and recommend a dedicated key-management capability such as a hardware security module.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The finding is acceptable provided the database administrator's activity is logged and reviewed monthly.

    Why it's wrong here

    Logging and review are detective controls that may support an investigation after a breach, but they do not prevent the administrator from copying the key and the data together. Monthly review is far too slow to stop exfiltration, and a privileged user can often alter or disable logging. Detection cannot substitute for the preventive separation that proper key management requires.

  • ✓

    The encryption is ineffective for protecting confidentiality because the key is exposed wherever the data is exposed.

    Why this is correct

    Encryption only protects data when the key is held separately from the ciphertext. Storing the key in a file readable by the same administrator who can already query the database removes the separation, so anyone who compromises that account obtains both the data and the means to decrypt it. The control provides no meaningful additional confidentiality against that threat, which is the auditor's central concern.

  • ✗

    The bank should migrate the keys to a hardware security module but may continue storing them with the database until the migration completes.

    Why it's wrong here

    A hardware security module is the right long-term destination, but the interim exposure is precisely the risk being reported. Advising continued co-location of keys and data, even temporarily, leaves cardholder data decryptable by the same account that accesses the database. An auditor should recommend immediate compensating controls and accelerated migration rather than endorsing an indefinite period of exposure.

  • ✗

    The encryption remains effective because AES-256 is computationally infeasible to break by brute force.

    Why it's wrong here

    Algorithm strength is irrelevant when the key is available in plaintext beside the data. An attacker or rogue administrator does not need to break AES-256; they simply read the configuration file and decrypt normally. Citing key length confuses cryptographic strength with key-management practice, and would lead the auditor to accept a control that fails against the most likely threat.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.