Courseiva
easyMultiple Choice

CISA Practice Question: An IS auditor reviews the exhibit

Exhibit

Refer to the exhibit.
```
Feb 20 10:15:32 firewall %ASA-4-106023: Deny tcp src outside:10.0.0.1/3389 dst inside:192.168.1.100/3389 by access-group "outside_in" [0x0, 0x0]
```

An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?

⚠ Common exam trap

Many candidates confuse a firewall deny with an IPS block or NAT failure, but the log entry's explicit 'denied' action and lack of IPS signature ID or NAT translation error point directly to a missing firewall rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Missing firewall rule allowing RDP traffic

The exhibit shows RDP traffic (TCP/3389) being denied at the firewall. Since the traffic reaches the firewall but is blocked, the most likely cause is a missing firewall rule that explicitly permits RDP traffic. A misconfigured VPN tunnel would typically prevent traffic from reaching the firewall at all, while an IPS block would generate an alert and often target specific signatures, not a blanket deny. Incorrect NAT would affect address translation but not cause a deny action at the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Misconfigured VPN tunnel

    Why it's wrong here

    A VPN tunnel encrypts traffic between remote peers; it does not filter or deny sessions traversing a firewall, so its misconfiguration would break connectivity rather than produce a logged deny. VPN faults are the likely cause when remote users cannot establish any connection at all.

  • ✗

    Intrusion prevention system blocking

    Why it's wrong here

    An IPS blocks traffic matching known attack signatures or anomaly thresholds, yet the exhibit shows a routine session denied by an explicit rule, with no alert or signature trigger recorded. IPS blocking is the correct diagnosis when logs show malicious payloads being dropped mid-session.

  • ✓

    Missing firewall rule allowing RDP traffic

    Why this is correct

    The exhibit shows the connection reaching the firewall but no matching permit entry, so the implicit deny rule drops the session. RDP requires an explicit inbound rule on port 3389; without it, traffic is denied. The missing firewall rule allowing RDP traffic is therefore the cause.

  • ✗

    Incorrect NAT configuration

    Why it's wrong here

    NAT rewrites source or destination addresses for translation, not policy decisions; an incorrect NAT rule would cause routing failure or unreachable addresses, not a rule-based deny entry. NAT misconfiguration fits scenarios where internal hosts cannot reach external services despite permissive firewall rules.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.