Which Network Access Poses the Highest Risk in a CISA Review?
A network review is being undertaken to evaluate security risks. Which of the following would be of MOST concern if identified during the review?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests risk prioritization by distinguishing between standard architectural components and uncontrolled endpoint exposure that lacks egress filtering.
This CISA question tests your ability to prioritize network security risks based on control maturity. Community consensus confirms that direct PC-to-internet access bypasses critical defenses, making it the most significant vulnerability.
Candidates often select C, mistakenly believing any external firewall connection is inherently dangerous, while overlooking that firewalls are standard protective layers designed precisely for this traffic.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Direct network access from PCs to the Internet (Option B) represents the highest risk because it completely bypasses essential security controls such as firewalls, proxies, and intrusion detection systems. Without intermediary filters, endpoints are immediately exposed to malware, phishing campaigns, and data exfiltration attempts. ISACA prioritizes uncontrolled outbound and inbound traffic because it eliminates audit trails and enforcement policies.Why the Other Options Are Wrong
Router access (A) and remote access (D) are standard, managed functions that typically operate within defined security perimeters. Option C describes a normal architectural component; firewalls are explicitly designed to handle internet-to-internal traffic, and the option lacks negative qualifiers like 'unrestricted' or 'misconfigured.' Therefore, they pose lower immediate risks compared to unfiltered endpoint exposure.Community Comment Notes
Several users correctly identified B, noting that 'direct access means no controls' [Comment 2]. While a minority argued for C based on inbound/outbound logic [Comment 6], experienced auditors recognize that unmonitored egress traffic often causes greater enterprise damage than filtered ingress. Comment 1 accurately highlights that direct PC connectivity removes all network-level governance.Exam Strategy
Focus on identifying missing security controls rather than assuming standard infrastructure components are problematic. When evaluating risk, prioritize scenarios where traffic bypasses firewalls, proxies, or logging mechanisms.
Frequently Asked Questions
Why is firewall access not the highest risk?
Firewalls are standard protective layers designed to filter internet traffic. Without qualifiers like 'unrestricted,' they represent normal architecture, not a vulnerability.
Does router access pose a greater threat than direct PC access?
No. Routers manage traffic routing and typically sit behind firewalls. Direct PC access bypasses all intermediate controls, enabling malware spread and data exfiltration.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →