CISA Information System Auditing Process Practice Question
An IS auditor is reviewing a network access control list and finds that a rule permits traffic from any source to a database server on port 1521. Management states the rule is required for a legacy application. Which of the following is the MOST appropriate audit response?
⚠ Common exam trap
The trap here is treating a documented business justification as equivalent to an acceptable level of residual risk, when the auditor must still evaluate the exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the rule as a finding with a recommendation to restrict source addresses to the application servers.
The auditor should identify the exposure created by an unrestricted database access rule and communicate it with a practical recommendation. Restricting the source addresses maintains the legacy application's function while reducing risk. Auditors report and recommend; they do not implement changes or accept risks on management's behalf. Escalation should follow the normal reporting process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the rule immediately to eliminate the exposure.
Why it's wrong here
Auditors do not modify production configurations; doing so would impair independence and could cause an outage. The auditor's role is to report risk and recommend remediation, not to implement changes. Removing the rule unilaterally would also bypass change management and could break the legacy application, creating an availability incident that the auditor would then have to explain.
- ✗
Accept the rule because management has provided a documented business justification.
Why it's wrong here
A business justification does not automatically make the rule acceptable. The auditor must assess whether the risk is mitigated to an acceptable level, and an any-source rule to a database port typically is not. Accepting the justification without evaluating compensating controls or narrower alternatives would fail to exercise professional skepticism and could leave a material exposure unreported.
- ✗
Escalate the matter directly to the board of directors without further analysis.
Why it's wrong here
Escalating to the board is disproportionate at this stage. The auditor should first assess the rule's context, compensating controls, and business need, then report through normal channels. Direct board escalation for a single rule bypasses the audit reporting hierarchy and may not be warranted if the risk is moderate or if management is responsive to a recommendation.
- ✓
Document the rule as a finding with a recommendation to restrict source addresses to the application servers.
Why this is correct
The rule permits unrestricted access to a database listener, which is a significant exposure regardless of the legacy justification. The auditor should document the risk and recommend tightening the source range to only the application servers that require access. This preserves functionality while reducing the attack surface, and it is the response most aligned with the auditor's role of identifying and communicating risk.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.