Any public IP address will be scanned for services, be it SIP, SSH, Winbox, HTTP(S) or anything else.
Just restricting SIP to your providers addresses is good practice to prevent direct access, unless you are running a SIP server which has to accept connections from anywhere.