CISA Protection of Information Assets Practice Question
An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?
⚠ Common exam trap
CISA often tests the hierarchy of key management controls — candidates pick rotation or generation because they sound proactive, but the exam expects recognition that secure storage is foundational because compromised keys nullify all other controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure key storage (e.g., HSM)
Secure key storage, typically in a hardware security module (HSM), is the most critical control because it protects keys at rest from extraction, tampering, and unauthorized access throughout their lifecycle. If keys can be stolen from storage, every other control — generation, rotation, destruction — is undermined, since the attacker gains the key material itself. HSMs provide tamper resistance, cryptographic isolation, and access controls that software storage cannot match.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secure key storage (e.g., HSM)
Why this is correct
Secure key storage in a hardware security module protects keys at rest within tamper-resistant hardware, preventing extraction or disclosure. Since compromise of the key itself defeats every cryptographic protection built upon it, this control is the most critical safeguard.
- ✗
Key rotation policy
Why it's wrong here
Rotation limits the exposure window of a compromised key but does not prevent initial compromise, so it is not the most critical control. It tempts because regular rotation is a recognised cryptographic hygiene practise, and would be the priority where keys are suspected leaked or must meet compliance lifetimes.
- ✗
Key generation in a secure environment
Why it's wrong here
Secure generation protects keys only at creation, leaving storage, distribution and use unprotected afterwards, so it is not the most critical control. It tempts because weak randomness or exposed generation hosts produce predictable keys, and would be the priority when provisioning hardware security modules or entropy sources.
- ✗
Key destruction procedures
Why it's wrong here
Destruction procedures only govern end-of-life removal, leaving keys exposed throughout their active lifetime, so they cannot be the most critical control. The option tempts because secure disposal prevents later recovery of retired keys, and would matter when decommissioning hardware or retiring compromised keys.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.