Certified Information Systems Auditor CISA · Free Practice Question Easy

Question 81

You are auditing HDA Inc. as an information system auditor, and your objective is to determine if a firewall is configured in accordance with the organization's security policy. What is the most effective audit procedure to achieve this goal?
  • A A. To review firewall parameter settings
  • B B. To conduct penetration testing on the firewall
  • C C. To analyze network traffic logs
  • D D. To verify firewall rule documentation against the security policy
Reveal correct answer

Correct answer: A

Explanation

Correct Answer: A. To review firewall parameter settings Explanation: Reviewing firewall parameter settings is the best audit procedure to determine whether a firewall is configured in compliance with the organization's security policy. Firewalls are an essential component of network security infrastructure and are responsible for controlling and monitoring network traffic based on predefined rules and policies. To ensure that the firewall is effectively protecting the organization's network, it is crucial to review its parameter settings. This includes examining configuration options such as access control rules, logging and monitoring settings, intrusion prevention settings, and any other relevant parameters. By reviewing the firewall parameter settings, the auditor can assess whether the configurations align with the organization's security policy. This involves verifying that the firewall is configured to allow authorized traffic and block unauthorized traffic, logging activities for audit purposes, and implementing appropriate security measures to prevent and detect intrusions. The other options are also relevant audit procedures, but they are not the BEST for determining compliance with the organization's security policy: - Option B suggests conducting penetration testing on the firewall. Penetration testing involves simulating real-world attacks to identify vulnerabilities and assess the effectiveness of security controls. While this is a valuable assessment technique, it focuses on identifying weaknesses rather than directly evaluating compliance with the security policy. - Option C suggests analyzing network traffic logs. Analyzing network traffic logs provides insights into the network activity and can help detect anomalies or potential security incidents. However, it does not directly assess the firewall's compliance with the security policy. - Option D suggests verifying firewall rule documentation against the security policy. This involves comparing the documented firewall rules with the requirements specified in the security policy. While this can help identify discrepancies, it does not provide a comprehensive assessment of the actual firewall configuration and its compliance with the policy. In summary, the BEST audit procedure for determining whether a firewall is configured in compliance with the organization's security policy is to review the firewall parameter settings. This enables the auditor to assess the alignment of the configuration with the policy requirements and ensure that the firewall is appropriately protecting the organization's network.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need