CISA Certified Information Systems Auditor – Question0205

An IS auditor discovered that a firewall has more services than needed. The IS auditor’s FIRST recommendation should be to:

A.
ensure logging is turned on.
B. deploy a network penetration team.
C. review configurations.
D. eliminate services except for HTTPS.

Correct Answer: C