Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?

⚠ Common exam trap

CISA often tests the auditor's role as an independent assessor who gathers evidence before recommending action, so the trap is selecting immediate escalation or removal instead of first determining business justification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs

The auditor's best course of action is to determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs, because audit findings must be based on evidence and business context rather than assumptions. A rule permitting any source IP to access TCP port 1433 is a significant security risk, but the auditor must first understand why it exists before recommending action. This approach ensures the recommendation is appropriate, justified, and aligned with business needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report the issue to senior management as a critical finding

    Why it's wrong here

    Escalating straight to senior management bypasses the established reporting route; findings normally go first to the process owner for a management response. It is tempting because the risk is severe, but immediate escalation is reserved for cases where management is complicit or unresponsive.

  • ✗

    Recommend immediate removal of the rule

    Why it's wrong here

    Removing the rule unilaterally exceeds the auditor's remit; auditors report and recommend, they do not implement changes. It is tempting because the exposure is genuine, yet remediation is management's decision, and the rule may still support a documented business need requiring a controlled fix.

  • ✗

    Accept the risk as a compensating control

    Why it's wrong here

    An any-source rule permitting direct SQL access is not a compensating control; it is the exposure itself, and no mitigating control is described. It is tempting because compensating controls can justify residual risk, but accepting risk is management's prerogative, not the auditor's.

  • ✓

    Determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs

    Why this is correct

    The rule permits unrestricted access to Microsoft SQL on TCP port 1433, a severe exposure. Validating business justification before recommending removal or IP restriction is proportionate: the auditor confirms whether the documented temporary need still exists, then addresses the actual risk rather than assuming misuse.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.