A firewall is a security control mechanism designed to prevent unauthorized access to or from a private network. It monitors and filters incoming and outgoing network traffic based on predefined security rules.
Definition of Control Types:
Preventive Control: Stops an undesirable event from occurring.
Detective Control: Identifies and records events after they have happened.
Corrective Control: Takes action to correct an issue after it has been detected.
Discretionary Control: Provides access control based on user discretion.
Why a Firewall is a Preventive Control:
Firewalls block unauthorized access to protect networks before a security breach can occur.
They enforce security policies in real-time, preventing cyber threats such as malware, intrusions, and unauthorized data access.
As per IIA GTAG (Global Technology Audit Guide) on Information Security, firewalls are categorized as preventive controls because they proactively mitigate threats before they materialize.
Why Not Other Options?
A. Corrective: Firewalls do not correct security breaches; they prevent them.
B. Detective: Firewalls do not just detect threats but actively block them.
D. Discretionary: Firewalls operate based on preset security rules rather than user discretion.
IIA GTAG – Information Security
IIA Standard 2110 – IT Governance & Risk Management
Step-by-Step Justification:IIA References:Thus, the correct and verified answer is C. Preventive.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit