Courseiva
easyMultiple ChoiceObjective-mapped

CISM Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.

---
Incident Log:
[2025-03-20 08:15:23] ALERT: Multiple failed logins for user 'jsmith' from IP 10.0.0.45
[2025-03-20 08:16:01] ALERT: Successful login for user 'jsmith' from IP 10.0.0.45
[2025-03-20 08:20:45] ALERT: Unusual outbound connection from host 10.0.0.45 to 198.51.100.10:4444
[2025-03-20 08:22:30] ALERT: Large data transfer from host 10.0.0.45 to 198.51.100.10
---

Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?

⚠ Common exam trap

ISACA often tests the distinction between a network scan and a targeted credential attack; the trap here is that candidates see the same source IP (10.0.0.45) and assume it's a scan, but the specific sequence of authentication failures followed by C2 and exfiltration indicates a successful compromise, not a reconnaissance scan.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attacker compromised jsmith's credentials, established C2, and exfiltrated data

The correct sequence is that an attacker compromised jsmith's credentials, established command-and-control (C2) communication, and then exfiltrated data. The alerts show a brute-force or credential-stuffing attempt from an external IP (10.0.0.45) against jsmith's account, followed by an outbound C2 beacon (e.g., DNS or HTTP) from jsmith's workstation, and finally a large data transfer to an external destination. This matches the typical kill chain: initial access via compromised credentials, persistence via C2, and data exfiltration as the final objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Insider threat: jsmith intentionally exfiltrated data

    Why it's wrong here

    Failed logins suggest compromise, not intentional action.

  • Attacker compromised jsmith's credentials, established C2, and exfiltrated data

    Why this is correct

    Pattern matches credential compromise, C2, and exfiltration.

  • Network scan from 10.0.0.45 triggered false positives

    Why it's wrong here

    Data transfer indicates exfiltration, not scan.

  • Malware downloaded on jsmith's workstation and exfiltrated data

    Why it's wrong here

    No download alert; failed logins indicate credential attack.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.