Which Network Access Poses the Highest Risk in a CISA Review?

Network Security Architecture
Answer Correct answer: B — Direct network access from PCs to the Internet bypasses critical security controls like firewalls and proxies, creating the highest risk.

A network review is being undertaken to evaluate security risks. Which of the following would be of MOST concern if identified during the review?

  1. Router access to the Internet from the internal network
  2. Direct network access from PCs to the Internet Correct Answer
  3. Firewall access to the internal network from the Internet
  4. Remote access to the internal network from internal PCs

Community Votes

C
67%
B
33%

67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests risk prioritization by distinguishing between standard architectural components and uncontrolled endpoint exposure that lacks egress filtering.

This CISA question tests your ability to prioritize network security risks based on control maturity. Community consensus confirms that direct PC-to-internet access bypasses critical defenses, making it the most significant vulnerability.

Candidates often select C, mistakenly believing any external firewall connection is inherently dangerous, while overlooking that firewalls are standard protective layers designed precisely for this traffic.

Community Discussion (6 comments)

MIMIBAK 👍 1 Selected: B
the question say "of concern" direct access means no controls
RS66 👍 1 Selected: C
C. Firewall access to the internal network from the Internet
joehong 👍 1 Selected: C
Yes is C. Incoming > outgoing
marc4354345 👍 2
My understanding is that B implies that there is no firewall nor proxy between the PC and the internet ("direct access"), which would indeed be the biggest problem. The formulation of C is unclear. What does "Firewall access" mean? It does not sound like direct external access.
MJORGER 👍 1
Agree C is correct. Options A, B, and D also represent security concerns, but they are typically less severe compared to direct firewall access from the Internet to the internal network.
Sibsankar 👍 1
Firewalls act as a barrier between internal networks and external networks like the Internet. Allowing unrestricted or unauthorized access through the firewall from the Internet to the internal network poses a significant security risk. The correct answer should be C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Direct network access from PCs to the Internet (Option B) represents the highest risk because it completely bypasses essential security controls such as firewalls, proxies, and intrusion detection systems. Without intermediary filters, endpoints are immediately exposed to malware, phishing campaigns, and data exfiltration attempts. ISACA prioritizes uncontrolled outbound and inbound traffic because it eliminates audit trails and enforcement policies.

Why the Other Options Are Wrong

Router access (A) and remote access (D) are standard, managed functions that typically operate within defined security perimeters. Option C describes a normal architectural component; firewalls are explicitly designed to handle internet-to-internal traffic, and the option lacks negative qualifiers like 'unrestricted' or 'misconfigured.' Therefore, they pose lower immediate risks compared to unfiltered endpoint exposure.

Community Comment Notes

Several users correctly identified B, noting that 'direct access means no controls' [Comment 2]. While a minority argued for C based on inbound/outbound logic [Comment 6], experienced auditors recognize that unmonitored egress traffic often causes greater enterprise damage than filtered ingress. Comment 1 accurately highlights that direct PC connectivity removes all network-level governance.

Exam Strategy

Focus on identifying missing security controls rather than assuming standard infrastructure components are problematic. When evaluating risk, prioritize scenarios where traffic bypasses firewalls, proxies, or logging mechanisms.

Frequently Asked Questions

Why is firewall access not the highest risk?

Firewalls are standard protective layers designed to filter internet traffic. Without qualifiers like 'unrestricted,' they represent normal architecture, not a vulnerability.

Does router access pose a greater threat than direct PC access?

No. Routers manage traffic routing and typically sit behind firewalls. Direct PC access bypasses all intermediate controls, enabling malware spread and data exfiltration.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide