mediumMultiple Choice
CISA Practice Question: An IS auditor for a financial institution that…
You are an IS auditor for a financial institution that processes credit card payments. The organization uses a key management system (KMS) to store encryption keys for point-of-sale (POS) data. The KMS is a hardware security module (HSM) located in a secured data center. The audit reveals that the HSM is administered by two individuals who both have full access to the HSM, including the ability to export keys. The organization has a policy requiring split knowledge and dual control for key management, but in practice, the two administrators often perform key ceremonies alone due to scheduling conflicts. The logs show that one administrator exported a key last month without the other present, and the export was approved via email by the other administrator after the fact. Which of the following is the BEST corrective action?
⚠ Common exam trap
Many exam-takers choose training (Option C) as a quick fix, overlooking that the root cause is a lack of technical enforcement, not a lack of awareness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the HSM to require two administrators to be physically present for key exports
The HSM must enforce split knowledge and dual control at the technical level, not rely on procedural compliance. By configuring the HSM to require two administrators to be physically present for key exports, the organization ensures that no single individual can export keys, directly addressing the policy violation and the log evidence of a solo export. This technical control is the most effective corrective action because it prevents the bypass of dual control even if administrators attempt to circumvent procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce the number of administrators to one to simplify accountability
Why it's wrong here
Single administrator violates segregation of duties.
- ✓
Configure the HSM to require two administrators to be physically present for key exports
Why this is correct
Enforcing dual physical presence at the HSM directly satisfies the split knowledge and dual control policy, preventing any single administrator from exporting keys alone. Email approval after the fact does not provide the required real-time, two-person authorisation during the key ceremony.
- ✗
Provide training to administrators on the importance of dual control
Why it's wrong here
Training addresses awareness, yet the logs show the administrators knowingly bypassed dual control for scheduling convenience, so instruction cannot enforce the physical two-person requirement. Training is the right remedy for genuine misunderstanding of procedures, not for deliberate, repeated circumvention of a mandated key ceremony control.
- ✗
Implement automated key rotation every 90 days
Why it's wrong here
Automated rotation changes key lifecycle frequency but does not require two authorised custodians during export or ceremony, leaving the single-administrator export path intact. Rotation is correct for limiting cryptoperiod exposure, whereas this finding concerns the separation of duties governing who can export keys.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.