CISM Information Security Program Practice Question
Exhibit
Refer to the exhibit. ``` Event Log: SIEM Alert #4521 Timestamp: 2024-08-15 14:23:45 UTC Rule: Failed login attempts > 5 in 10 minutes Source IP: 203.0.113.5 Target: User 'admin' on server DC-01 Count: 12 attempts Status: Alert generated, no automated action Comment: IP belongs to external VPN broker ```
The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?
⚠ Common exam trap
Many candidates assume a trusted source IP (VPN broker) automatically means the traffic is legitimate, overlooking the common attack pattern where compromised endpoints are used to launch internal attacks from an authorized network path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker has compromised a remote employee's device and is brute-forcing the admin account
A trusted VPN broker IP address in a SIEM alert for brute-force attempts against an admin account strongly indicates that an attacker has compromised a remote employee's device and is using the established VPN tunnel to launch the attack. The VPN broker itself is not misconfigured; rather, the attacker is leveraging the legitimate VPN connection to bypass perimeter defenses and target internal systems, making the alert a valid security incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPN broker itself is misconfigured
Why it's wrong here
A misconfigured VPN broker could route traffic unexpectedly, but the stem offers no configuration evidence, and the alert's source alone does not indicate broker fault. It is tempting because infrastructure misconfiguration is a known cause of odd SIEM alerts, and would be correct if logs showed broker routing or policy errors.
- ✗
A legitimate user forgot their password
Why it's wrong here
A forgotten password produces failed authentication attempts, but the source being a trusted VPN broker does not by itself explain the alert's nature; the stem gives no evidence of credential misuse. It is tempting because helpdesk password resets are common, and would fit if the alert were repeated failed logons from that broker.
- ✓
An attacker has compromised a remote employee's device and is brute-forcing the admin account
Why this is correct
A compromised remote endpoint tunnelling through the trusted VPN broker would present that broker's source IP while the attacker brute-forces the admin account, explaining the SIEM alert. This satisfies the stem's constraint that the source IP belongs to a legitimate VPN service.
- ✗
The alert is a false positive due to SIEM rule threshold
Why it's wrong here
A trusted VPN broker's source IP does not by itself make the alert benign; the SIEM rule fired on actual session behaviour, so the threshold explanation ignores the matched signature. Threshold tuning addresses alert volume from repeated identical events, which is the scenario where this would be correct.
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.