Courseiva

CISM Information Security Program Practice Question

Exhibit

Refer to the exhibit.
```
Event Log: SIEM Alert #4521
Timestamp: 2024-08-15 14:23:45 UTC
Rule: Failed login attempts > 5 in 10 minutes
Source IP: 203.0.113.5
Target: User 'admin' on server DC-01
Count: 12 attempts
Status: Alert generated, no automated action
Comment: IP belongs to external VPN broker
```

The security analyst reviews the SIEM alert and finds that the source IP is from a trusted VPN broker used by remote employees. What is the most likely explanation for the alert?

⚠ Common exam trap

Many candidates assume a trusted source IP (VPN broker) automatically means the traffic is legitimate, overlooking the common attack pattern where compromised endpoints are used to launch internal attacks from an authorized network path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An attacker has compromised a remote employee's device and is brute-forcing the admin account

A trusted VPN broker IP address in a SIEM alert for brute-force attempts against an admin account strongly indicates that an attacker has compromised a remote employee's device and is using the established VPN tunnel to launch the attack. The VPN broker itself is not misconfigured; rather, the attacker is leveraging the legitimate VPN connection to bypass perimeter defenses and target internal systems, making the alert a valid security incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPN broker itself is misconfigured

    Why it's wrong here

    A misconfigured VPN broker could route traffic unexpectedly, but the stem offers no configuration evidence, and the alert's source alone does not indicate broker fault. It is tempting because infrastructure misconfiguration is a known cause of odd SIEM alerts, and would be correct if logs showed broker routing or policy errors.

  • ✗

    A legitimate user forgot their password

    Why it's wrong here

    A forgotten password produces failed authentication attempts, but the source being a trusted VPN broker does not by itself explain the alert's nature; the stem gives no evidence of credential misuse. It is tempting because helpdesk password resets are common, and would fit if the alert were repeated failed logons from that broker.

  • ✓

    An attacker has compromised a remote employee's device and is brute-forcing the admin account

    Why this is correct

    A compromised remote endpoint tunnelling through the trusted VPN broker would present that broker's source IP while the attacker brute-forces the admin account, explaining the SIEM alert. This satisfies the stem's constraint that the source IP belongs to a legitimate VPN service.

  • ✗

    The alert is a false positive due to SIEM rule threshold

    Why it's wrong here

    A trusted VPN broker's source IP does not by itself make the alert benign; the SIEM rule fired on actual session behaviour, so the threshold explanation ignores the matched signature. Threshold tuning addresses alert volume from repeated identical events, which is the scenario where this would be correct.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.