Courseiva

CISA Protection of Information Assets Practice Question

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

⚠ Common exam trap

CISA often tests the temptation to recommend immediate deletion of risky rules, when the correct audit approach is justification, replacement, and controlled removal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain business justification for each any-to-any rule

Option A is correct because an IS auditor must first obtain business justification for each any-to-any rule, since a rule may be required for a legitimate business or technical purpose and cannot be judged in isolation. Option B is correct because the fundamental remediation for overly permissive rules is to replace any-to-any rules with specific source, destination, port, and protocol rules that enforce least privilege and reduce the attack surface. Option E is correct because any any-to-any rule that lacks a valid business justification should be removed, as it represents unnecessary exposure with no documented need. Option C is not appropriate because immediately deleting all any-to-any rules without review could disrupt legitimate business traffic and cause outages, violating change management and availability requirements. Option D is not the most appropriate action because increasing logging only detects misuse after the fact; it does not remediate the excessive permissiveness that the auditor should recommend eliminating.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Obtain business justification for each any-to-any rule

    Why this is correct

    Any-to-any rules bypass least privilege, so the auditor must first establish why each exists. Obtaining business justification determines whether the rule is genuinely required, enabling informed decisions to tighten, replace or remove it rather than blindly deleting needed connectivity.

  • ✓

    Replace any-to-any rules with specific source/destination rules

    Why this is correct

    Any-to-any rules permit unrestricted traffic, violating least privilege and network segmentation. Replacing them with specific source and destination rules restricts flows to only what business requires, directly reducing the attack surface exposed by overly permissive firewall configurations.

  • ✗

    Immediately delete all any-to-any rules without review

    Why it's wrong here

    Deleting rules outright risks outage by removing traffic that may be legitimately required; each rule needs business justification and impact analysis first. Immediate deletion suits only confirmed malicious or unused rules. The recommendation should be review, then restrict or remove with change control.

  • ✗

    Increase logging for any-to-any rules to detect misuse

    Why it's wrong here

    Logging only records traffic; it neither restricts the excessive any-to-any access nor remediates the finding. The auditor should recommend tightening or removing the permissive rules. Enhanced logging is appropriate as a compensating detective control while remediation is pending, not as the primary action.

  • ✓

    Remove any-to-any rules that lack business justification

    Why this is correct

    Rules lacking documented business justification serve no legitimate purpose and represent unjustified exposure. Removing them eliminates unnecessary attack surface and enforces least privilege, directly addressing the any-to-any weakness the auditor identified during the firewall rule review.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.