CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?
⚠ Common exam trap
The trap is equating 'any source IP' with 'any service'; candidates see 'any source' in option C and pick it, missing that the protocol and destination are restricted, whereas option D allows any service to the entire internal network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A rule that allows any service from the Internet to the internal network
A rule that allows any service from the Internet to the internal network is the most concerning because it effectively bypasses the firewall's purpose, permitting unrestricted inbound access to internal systems. This exposes the entire internal network to external threats, including malware, unauthorized access, and exploitation of any vulnerable service. Such a rule violates the principle of least privilege and is a critical misconfiguration that auditors flag as a severe control weakness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A rule that has not been reviewed for 18 months
Why it's wrong here
An 18-month review gap is a documentation and governance weakness, not an active exposure; the question asks for the finding of most concern. It is tempting because stale rules violate change-management hygiene, and in an audit focused purely on rule-review cadence this would be the correct finding.
- ✗
A rule that permits traffic from a specific IP to a database server on port 1433
Why it's wrong here
Port 1433 is SQL Server's default, not Oracle's, so this rule targets the wrong service and is irrelevant to the scenario. It is tempting because a database-port rule scoped to one source IP looks tightly restricted, and such a rule would be acceptable for a known application server accessing a specific database.
- ✗
A rule that allows any source IP to access a critical server on port 443
Why it's wrong here
Port 443 is HTTPS, so any-source access to a critical server is common for public web services and may be intentional. Greater concern arises from rules permitting unencrypted administrative protocols, such as Telnet or SMB, from untrusted networks into critical hosts.
- ✓
A rule that allows any service from the Internet to the internal network
Why this is correct
A rule permitting any service from the Internet to the internal network exposes every internal host and port to unrestricted external access, effectively bypassing perimeter segmentation. This is the most severe finding because it enables broad exploitation, far exceeding risks from individual permissive rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.