Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner is reviewing the organization's cryptographic key management practices after an audit finding. Which TWO of the following practices are MOST important to protect the confidentiality and integrity of cryptographic keys throughout their lifecycle? (Choose two.)

⚠ Common exam trap

The trap here is selecting administrative documentation or convenience-driven practices as if they protected the key material itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define and enforce a cryptoperiod for each key type with scheduled rotation and retirement.

Protecting keys across their lifecycle requires both a secure execution and storage environment and disciplined lifecycle governance. Hardware security modules or managed vaults keep key material confidential and enforce access, while a defined cryptoperiod with rotation and retirement limits how much data any single key protects. Email distribution of backups, shared master keys across environments, and custodian documentation do not provide these protections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Document key custodians in the configuration management database and review the list annually.

    Why it's wrong here

    Recording key custodians and reviewing annually supports accountability and is good governance, but it is an administrative record rather than a protection of key material. It does not prevent key exposure, enforce access, or bound key lifetime, so on its own it cannot remediate a finding about protecting keys throughout their lifecycle.

  • ✓

    Define and enforce a cryptoperiod for each key type with scheduled rotation and retirement.

    Why this is correct

    A defined cryptoperiod limits the volume of data protected by a single key and bounds the damage if a key is compromised. Scheduled rotation, rekeying, and secure retirement ensure keys do not outlive their intended use, satisfying lifecycle governance requirements and reducing exposure from undetected key compromise.

  • ✗

    Use the same master key across all environments to simplify key management and reduce operational cost.

    Why it's wrong here

    Sharing a master key across production, test, and development environments destroys blast-radius containment; compromise or insider misuse in a lower environment exposes production data. Environment separation of keys is a baseline requirement, and cost savings do not justify the resulting enterprise-wide cryptographic exposure.

  • ✗

    Email encrypted key backups to the security team's shared mailbox for disaster recovery availability.

    Why it's wrong here

    Distributing key material through email exposes it to mailbox compromise, forwarding, and uncontrolled retention, defeating the purpose of key protection. Key backups belong in an encrypted, access-controlled escrow with split knowledge or dual control. This practice would worsen the audit finding rather than remediate it.

  • ✓

    Store keys in a hardware security module (HSM) or managed key vault with strict access controls.

    Why this is correct

    Hardware security modules and managed key vaults generate and store keys in tamper-resistant hardware, perform cryptographic operations without exposing key material, and enforce role-based access. This directly protects key confidentiality and integrity across generation, storage, and use, which is why it is a foundational control for the audit finding.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.