nerdexam
Isaca

CISA · Question #553

An IS auditor is examining cryptographic key management with a focus on ensuring the protection of cryptographic keys against modification and unauthorized disclosure. Which of the following should…

The correct answer is D. Key policies. Key management policies should be reviewed first because they define how cryptographic keys are generated, stored, distributed, used, rotated, and destroyed. Reviewing these policies establishes whether appropriate governance and controls exist to prevent unauthorized…

Submitted by fernanda_arg· Apr 18, 2026Protection of Information Assets

Question

An IS auditor is examining cryptographic key management with a focus on ensuring the protection of cryptographic keys against modification and unauthorized disclosure. Which of the following should be reviewed FIRST?

Options

  • AKey storage
  • BKey rotation
  • CKey generation
  • DKey policies

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    17% (5)
  • C
    7% (2)
  • D
    72% (21)

Explanation

Key management policies should be reviewed first because they define how cryptographic keys are generated, stored, distributed, used, rotated, and destroyed. Reviewing these policies establishes whether appropriate governance and controls exist to prevent unauthorized disclosure or modification of keys before assessing technical implementations.

Topics

#Cryptographic key management#Information security policies#IS audit methodology#Protection of information assets

Community Discussion

No community discussion yet for this question.

Full CISA Practice