easyMultiple Choice
CISA Practice Question: An IS auditor reviews the exhibit
Exhibit
Refer to the exhibit. ``` Feb 20 10:15:32 firewall %ASA-4-106023: Deny tcp src outside:10.0.0.1/3389 dst inside:192.168.1.100/3389 by access-group "outside_in" [0x0, 0x0] ```
An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?
⚠ Common exam trap
Many candidates confuse a firewall deny with an IPS block or NAT failure, but the log entry's explicit 'denied' action and lack of IPS signature ID or NAT translation error point directly to a missing firewall rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Missing firewall rule allowing RDP traffic
The exhibit shows RDP traffic (TCP/3389) being denied at the firewall. Since the traffic reaches the firewall but is blocked, the most likely cause is a missing firewall rule that explicitly permits RDP traffic. A misconfigured VPN tunnel would typically prevent traffic from reaching the firewall at all, while an IPS block would generate an alert and often target specific signatures, not a blanket deny. Incorrect NAT would affect address translation but not cause a deny action at the firewall.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Misconfigured VPN tunnel
Why it's wrong here
A VPN tunnel encrypts traffic between remote peers; it does not filter or deny sessions traversing a firewall, so its misconfiguration would break connectivity rather than produce a logged deny. VPN faults are the likely cause when remote users cannot establish any connection at all.
- ✗
Intrusion prevention system blocking
Why it's wrong here
An IPS blocks traffic matching known attack signatures or anomaly thresholds, yet the exhibit shows a routine session denied by an explicit rule, with no alert or signature trigger recorded. IPS blocking is the correct diagnosis when logs show malicious payloads being dropped mid-session.
- ✓
Missing firewall rule allowing RDP traffic
Why this is correct
The exhibit shows the connection reaching the firewall but no matching permit entry, so the implicit deny rule drops the session. RDP requires an explicit inbound rule on port 3389; without it, traffic is denied. The missing firewall rule allowing RDP traffic is therefore the cause.
- ✗
Incorrect NAT configuration
Why it's wrong here
NAT rewrites source or destination addresses for translation, not policy decisions; an incorrect NAT rule would cause routing failure or unreachable addresses, not a rule-based deny entry. NAT misconfiguration fits scenarios where internal hosts cannot reach external services despite permissive firewall rules.
Visual reference
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.