CISA Protection of Information Assets Practice Question
An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?
⚠ Common exam trap
CISA often tests the auditor's role as an independent assessor who gathers evidence before recommending action, so the trap is selecting immediate escalation or removal instead of first determining business justification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs
The auditor's best course of action is to determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs, because audit findings must be based on evidence and business context rather than assumptions. A rule permitting any source IP to access TCP port 1433 is a significant security risk, but the auditor must first understand why it exists before recommending action. This approach ensures the recommendation is appropriate, justified, and aligned with business needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report the issue to senior management as a critical finding
Why it's wrong here
Escalating straight to senior management bypasses the established reporting route; findings normally go first to the process owner for a management response. It is tempting because the risk is severe, but immediate escalation is reserved for cases where management is complicit or unresponsive.
- ✗
Recommend immediate removal of the rule
Why it's wrong here
Removing the rule unilaterally exceeds the auditor's remit; auditors report and recommend, they do not implement changes. It is tempting because the exposure is genuine, yet remediation is management's decision, and the rule may still support a documented business need requiring a controlled fix.
- ✗
Accept the risk as a compensating control
Why it's wrong here
An any-source rule permitting direct SQL access is not a compensating control; it is the exposure itself, and no mitigating control is described. It is tempting because compensating controls can justify residual risk, but accepting risk is management's prerogative, not the auditor's.
- ✓
Determine if there is a business justification for the rule and, if not, recommend removal or restriction to specific IPs
Why this is correct
The rule permits unrestricted access to Microsoft SQL on TCP port 1433, a severe exposure. Validating business justification before recommending removal or IP restriction is proportionate: the auditor confirms whether the documented temporary need still exists, then addresses the actual risk rather than assuming misuse.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.