Exam CISA All QuestionsBrowse all questions from this exam
Question 665

If enabled within firewall rules, which of the following services would present the GREATEST risk?

    Correct Answer: A

    File transfer protocol (FTP) presents the greatest risk because it transmits data, including user credentials, in plaintext. This lack of encryption means that data can be easily intercepted and compromised by attackers. Other protocols, such as HTTP and SMTP, have mechanisms to secure data transmission (e.g., HTTPS for HTTP and encryption options for SMTP), while FTP does not have built-in security features, making it the riskiest option to enable within firewall rules.

Discussion
SwallowsOption: A

FTP is inherently less secure compared to other protocols like HTTP because it transfers data, including credentials, in plaintext. This makes it vulnerable to interception and unauthorized access. Therefore, enabling FTP within firewall rules could expose sensitive information to potential attackers.

Yejide03Option: C

C. Hypertext transfer protocol (HTTP)