CISA Protection of Information Assets Practice Question
During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?
⚠ Common exam trap
CISA often tests the principle of least privilege in key management, and candidates may focus on secondary concerns like performance or compliance, missing the primary risk of a single key compromise leading to widespread data exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increased risk of data exposure if the key is compromised
Using the same encryption key for all customer data at rest creates a single point of failure: if that key is compromised, all encrypted data becomes exposed. This is the primary concern because it violates the principle of key separation and significantly amplifies the impact of a key breach. While other issues like performance or compliance may exist, the immediate and severe risk is the potential for mass data exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performance degradation due to key reuse
Why it's wrong here
Key reuse does not degrade cryptographic performance; throughput is governed by algorithm and hardware, not key count. A single shared key is tempting because it simplifies key management, which is legitimate for low-sensitivity, non-segregated data — but here it destroys per-customer cryptographic isolation.
- ✗
Inability to revoke access to specific data
Why it's wrong here
Revoking access to specific data is achievable by deleting that data or rotating the shared key, so this is not the primary concern. Per-customer keys are tempting for granular revocation, but the real issue with one key is that a single compromise decrypts all customers' data at rest.
- ✗
Non-compliance with GDPR pseudonymization requirements
Why it's wrong here
GDPR pseudonymisation does not mandate unique per-subject keys; encryption with a single key still pseudonymises data. Citing this regulation is tempting because encryption is a recognised safeguard, but the actual concern is that one key compromise exposes every customer's data simultaneously.
- ✓
Increased risk of data exposure if the key is compromised
Why this is correct
A single shared key means one compromise decrypts every customer's data at rest, eliminating any blast-radius containment. Per-customer or per-tenant keys would limit exposure to one dataset; key reuse converts an isolated incident into organisation-wide data exposure.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.