Courseiva
Information Security ProgramhardMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

Exhibit

Refer to the exhibit.
```
Event Log: SIEM Alert #4521
Timestamp: 2024-08-15 14:23:45 UTC
Rule: Failed login attempts > 5 in 10 minutes
Source IP: 203.0.113.5
Target: User 'admin' on server DC-01
Count: 12 attempts
Status: Alert generated, no automated action
Comment: IP belongs to external VPN broker
```

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

⚠ Common exam trap

Many candidates assume a trusted source IP (VPN broker) automatically means the traffic is legitimate, overlooking the common attack pattern where compromised endpoints are used to launch internal attacks from an authorized network path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An attacker has compromised a remote employee's device and is brute-forcing the admin account

A trusted VPN broker IP address in a SIEM alert for brute-force attempts against an admin account strongly indicates that an attacker has compromised a remote employee's device and is using the established VPN tunnel to launch the attack. The VPN broker itself is not misconfigured; rather, the attacker is leveraging the legitimate VPN connection to bypass perimeter defenses and target internal systems, making the alert a valid security incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The VPN broker itself is misconfigured

    Why it's wrong here

    VPN broker typically does not generate login attempts.

  • A legitimate user forgot their password

    Why it's wrong here

    12 attempts in 10 minutes is excessive.

  • An attacker has compromised a remote employee's device and is brute-forcing the admin account

    Why this is correct

    Source IP is VPN broker, but device behind it could be compromised.

  • The alert is a false positive due to SIEM rule threshold

    Why it's wrong here

    Pattern is suspicious; not a false positive.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.