Courseiva

CISA Protection of Information Assets Practice Question

During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?

⚠ Common exam trap

CISA often tests the principle of least privilege in key management, and candidates may focus on secondary concerns like performance or compliance, missing the primary risk of a single key compromise leading to widespread data exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increased risk of data exposure if the key is compromised

Using the same encryption key for all customer data at rest creates a single point of failure: if that key is compromised, all encrypted data becomes exposed. This is the primary concern because it violates the principle of key separation and significantly amplifies the impact of a key breach. While other issues like performance or compliance may exist, the immediate and severe risk is the potential for mass data exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performance degradation due to key reuse

    Why it's wrong here

    Key reuse does not degrade cryptographic performance; throughput is governed by algorithm and hardware, not key count. A single shared key is tempting because it simplifies key management, which is legitimate for low-sensitivity, non-segregated data — but here it destroys per-customer cryptographic isolation.

  • ✗

    Inability to revoke access to specific data

    Why it's wrong here

    Revoking access to specific data is achievable by deleting that data or rotating the shared key, so this is not the primary concern. Per-customer keys are tempting for granular revocation, but the real issue with one key is that a single compromise decrypts all customers' data at rest.

  • ✗

    Non-compliance with GDPR pseudonymization requirements

    Why it's wrong here

    GDPR pseudonymisation does not mandate unique per-subject keys; encryption with a single key still pseudonymises data. Citing this regulation is tempting because encryption is a recognised safeguard, but the actual concern is that one key compromise exposes every customer's data simultaneously.

  • ✓

    Increased risk of data exposure if the key is compromised

    Why this is correct

    A single shared key means one compromise decrypts every customer's data at rest, eliminating any blast-radius containment. Per-customer or per-tenant keys would limit exposure to one dataset; key reuse converts an isolated incident into organisation-wide data exposure.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.