CISA Protection of Information Assets Practice Question
During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine if the rule has a documented business justification.
The first step is to verify the business justification for the rule, as it may be necessary for a specific application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Test whether the rule is actually being used.
Why it's wrong here
Usage testing may follow, but the initial step is to check authorization.
- ✗
Escalate the finding to senior management.
Why it's wrong here
Escalation is premature before understanding the context.
- ✓
Determine if the rule has a documented business justification.
Why this is correct
The auditor should first check if the rule is authorized and necessary.
- ✗
Recommend immediate removal of the rule.
Why it's wrong here
Removal without understanding business need could disrupt operations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.