easyMultiple ChoiceObjective-mapped
CISM Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. --- Incident Log: [2025-03-20 08:15:23] ALERT: Multiple failed logins for user 'jsmith' from IP 10.0.0.45 [2025-03-20 08:16:01] ALERT: Successful login for user 'jsmith' from IP 10.0.0.45 [2025-03-20 08:20:45] ALERT: Unusual outbound connection from host 10.0.0.45 to 198.51.100.10:4444 [2025-03-20 08:22:30] ALERT: Large data transfer from host 10.0.0.45 to 198.51.100.10 ---
Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?
⚠ Common exam trap
ISACA often tests the distinction between a network scan and a targeted credential attack; the trap here is that candidates see the same source IP (10.0.0.45) and assume it's a scan, but the specific sequence of authentication failures followed by C2 and exfiltration indicates a successful compromise, not a reconnaissance scan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attacker compromised jsmith's credentials, established C2, and exfiltrated data
The correct sequence is that an attacker compromised jsmith's credentials, established command-and-control (C2) communication, and then exfiltrated data. The alerts show a brute-force or credential-stuffing attempt from an external IP (10.0.0.45) against jsmith's account, followed by an outbound C2 beacon (e.g., DNS or HTTP) from jsmith's workstation, and finally a large data transfer to an external destination. This matches the typical kill chain: initial access via compromised credentials, persistence via C2, and data exfiltration as the final objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Insider threat: jsmith intentionally exfiltrated data
Why it's wrong here
Failed logins suggest compromise, not intentional action.
- ✓
Attacker compromised jsmith's credentials, established C2, and exfiltrated data
Why this is correct
Pattern matches credential compromise, C2, and exfiltration.
- ✗
Network scan from 10.0.0.45 triggered false positives
Why it's wrong here
Data transfer indicates exfiltration, not scan.
- ✗
Malware downloaded on jsmith's workstation and exfiltrated data
Why it's wrong here
No download alert; failed logins indicate credential attack.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.