CISA Protection of Information Assets Practice Question
An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?
⚠ Common exam trap
CISA often tests the difference between rule review (policy and documentation validation) and firewall operational testing (failover, performance, password checks); candidates who pick operational tasks miss the 'rule review' scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verifying that each rule has a business justification
A firewall rule review is fundamentally about validating the rulebase itself, so option B is correct: verifying that each rule has a business justification ensures no unnecessary, stale, or overly permissive rules remain, directly supporting least-privilege and reducing the attack surface. Option C is also correct because comparing the actual running rulebase against the documented/approved rules detects unauthorized changes, configuration drift, and shadowed or redundant rules, which is the core purpose of a rule review. Option A is not a rule-review element but a configuration/hardening check for default credentials, which is a separate control. Option D concerns resilience and availability testing (failover), not rule correctness, and option E addresses capacity/performance monitoring rather than the appropriateness of the rules themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Checking for default passwords on firewall
Why it's wrong here
Default passwords concern device hardening and administrative access, not the content or ordering of the rule base being reviewed. It is tempting because weak credentials are a genuine firewall weakness, but checking them is correct during a configuration or hardening assessment, not a firewall rule review.
- ✓
Verifying that each rule has a business justification
Why this is correct
Each firewall rule must map to a documented business need; rules lacking justification are candidates for removal, reducing attack surface. This satisfies the stem's rule-review element by confirming every permitted flow is authorised rather than merely technically functional.
- ✓
Comparing actual rules to documented rules
Why this is correct
Comparing deployed rules against documented ones detects drift, unauthorised changes and undocumented shadowing rules. This satisfies the stem's rule-review element by verifying the firewall's actual configuration matches its approved baseline, exposing discrepancies that documentation review alone would miss.
- ✗
Testing firewall failover capabilities
Why it's wrong here
Failover testing verifies redundancy and availability of the firewall platform, not the correctness, necessity or ordering of individual rules. It is tempting because resilience matters to network security, but failover testing is the right control when auditing high-availability design, not rule-base content.
- ✗
Reviewing firewall performance metrics
Why it's wrong here
Performance metrics such as throughput and latency describe how well the firewall forwards traffic, not whether its rule set is correct, excessive or contradictory. Reviewing them is tempting because they evidence operational health, but that belongs to capacity and availability auditing, not a rule-base review.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.