CISM Information Security Program Practice Question
Exhibit
Refer to the exhibit. ``` Event Log: SIEM Alert #4521 Timestamp: 2024-08-15 14:23:45 UTC Rule: Failed login attempts > 5 in 10 minutes Source IP: 203.0.113.5 Target: User 'admin' on server DC-01 Count: 12 attempts Status: Alert generated, no automated action Comment: IP belongs to external VPN broker ```
The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?
⚠ Common exam trap
Many candidates assume a trusted source IP (VPN broker) automatically means the traffic is legitimate, overlooking the common attack pattern where compromised endpoints are used to launch internal attacks from an authorized network path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker has compromised a remote employee's device and is brute-forcing the admin account
A trusted VPN broker IP address in a SIEM alert for brute-force attempts against an admin account strongly indicates that an attacker has compromised a remote employee's device and is using the established VPN tunnel to launch the attack. The VPN broker itself is not misconfigured; rather, the attacker is leveraging the legitimate VPN connection to bypass perimeter defenses and target internal systems, making the alert a valid security incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPN broker itself is misconfigured
Why it's wrong here
VPN broker typically does not generate login attempts.
- ✗
A legitimate user forgot their password
Why it's wrong here
12 attempts in 10 minutes is excessive.
- ✓
An attacker has compromised a remote employee's device and is brute-forcing the admin account
Why this is correct
Source IP is VPN broker, but device behind it could be compromised.
- ✗
The alert is a false positive due to SIEM rule threshold
Why it's wrong here
Pattern is suspicious; not a false positive.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.