Correct Answer: C
* Definition of a Firewall:
* A firewall is a network security device (hardware or software) that monitors and controls incoming and outgoing network traffic.
* It is designed to filter or prevent specific information from moving between internal and external networks, ensuring unauthorized access is blocked.
* How a Firewall Works:
* It uses rules and policies to determine whether to allow or block traffic.
* Firewalls can be configured to prevent malware, hacking attempts, and unauthorized data transfers.
* There are different types, including packet-filtering firewalls, stateful inspection firewalls, and next-generation firewalls (NGFWs).
* Why Other Options Are Incorrect:
* A. Authorization:
* Authorization refers to user access control, ensuring users have the correct permissions, but it does not filter network traffic.
* B. Architecture model:
* An architecture model defines the structure of an IT system but does not actively prevent or filter data movement.
* D. Virtual private network (VPN):
* A VPN encrypts data and provides secure remote access but does not filter or block data movement between networks.
* IIA's Perspective on IT Security Controls:
* IIA Standard 2110 - Governance emphasizes strong cybersecurity controls, including firewalls, to protect sensitive data.
* IIA GTAG (Global Technology Audit Guide) on Information Security recommends using firewalls as a primary defense mechanism.
* NIST Cybersecurity Framework and ISO 27001 Security Standards identify firewalls as critical tools for network security and data protection.
IIA References:
* IIA Standard 2110 - Governance and IT Security
* IIA GTAG - Information Security Risks
* NIST Cybersecurity Framework