CISA Protection of Information Assets Practice Question
An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?
⚠ Common exam trap
CISA often tests the hierarchy of key protection controls; candidates may choose key rotation or separation of duties because they sound like strong controls, but the question asks for the MOST important control to ensure key security, which is hardware-based protection (HSM).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Storing keys in a hardware security module (HSM)
Storing keys in a hardware security module (HSM) is the most important control because HSMs provide tamper-resistant hardware that protects keys from extraction, ensures cryptographic operations occur inside a secure boundary, and enforces access controls. This directly addresses the core security objective of key protection. Other controls like separation of duties, rotation, and key wrapping are important but secondary to secure storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separating key management duties
Why it's wrong here
Separating key management duties, such as splitting custody between administrators, reduces single-person misuse but does not protect keys at rest or in transit. It suits governance over privileged staff. Cryptographic protection of the keys themselves, through hardware security modules or envelope encryption, is the primary control.
- ✓
Storing keys in a hardware security module (HSM)
Why this is correct
An HSM generates, stores and uses keys inside tamper-resistant hardware, so plaintext key material never enters general memory or storage. This satisfies the programme's core requirement to protect keys from extraction, unlike software storage or file-based encryption, where compromise of the host exposes the keys.
- ✗
Regular key rotation
Why it's wrong here
Rotation limits the exposure window of a compromised key but does nothing to stop extraction or misuse of the currently active key; it is a lifecycle hygiene measure. It would be the right control where regulatory policy mandates cryptoperiod limits, not where the primary threat is unauthorised key disclosure.
- ✗
Encrypting keys with a master key
Why it's wrong here
Wrapping keys under a master key protects them at rest, yet the master key itself still requires hardware-backed storage and strict access control, so this alone does not secure the hierarchy. It is the correct choice when keys must be stored outside an HSM, such as in application configuration.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.