CISA Protection of Information Assets Practice Question
During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?
⚠ Common exam trap
The trap is accepting a business justification as sufficient for an overly broad rule; CISA tests that auditors must still recommend least-privilege restrictions even when a justification exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a more restrictive rule set based on specific IP addresses and ports
An any-to-any rule from internal to Internet is overly permissive and violates the principle of least privilege, even if a business justification exists. The auditor's best recommendation is to implement a more restrictive rule set based on specific IP addresses, ports, and protocols, which enforces least privilege while still meeting business needs. A business justification does not make an overly broad rule acceptable; the control should be tightened to the minimum necessary access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an intrusion prevention system (IPS) to monitor the traffic
Why it's wrong here
An IPS monitors and can block malicious traffic but leaves the unrestricted any-to-any rule intact, so the underlying least-privilege violation persists. It is tempting because IPS adds detection and prevention value, and would be correct as a layered control once the firewall rule itself has been tightened to required ports and destinations.
- ✗
Require all traffic to go through a proxy server
Why it's wrong here
Routing all traffic through a proxy imposes a blanket architectural change that breaks protocols and applications the any-to-any rule legitimately supports, exceeding what the finding requires. It is tempting because proxies inspect and control outbound traffic, and would be correct where content filtering or egress inspection is the stated control objective.
- ✓
Implement a more restrictive rule set based on specific IP addresses and ports
Why this is correct
Any-to-any internal-to-Internet access grants unrestricted egress, enabling data exfiltration and command-and-control. Restricting to specific IP addresses and ports enforces least privilege while preserving the justified business need, satisfying the stem's requirement for a more granular, auditable rule set.
- ✗
Accept the risk because there is a business justification
Why it's wrong here
Accepting the risk leaves the any-to-any rule in place, so the auditor endorses the exposure rather than recommending remediation; business justification does not remove the need for compensating controls. It is tempting because justified rules are legitimate, and acceptance would be correct only when risk is formally accepted by management within tolerance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.