Courseiva
hardMultiple Choice

CRISC Practice Question: Based on the exhibit, what is the MOST likely…

Exhibit

Refer to the exhibit.
```
2023-11-15 14:23:45 [CRITICAL] Failed login attempt for user 'admin' from IP 10.0.0.5
2023-11-15 14:23:46 [CRITICAL] Failed login attempt for user 'admin' from IP 10.0.0.5
2023-11-15 14:23:47 [CRITICAL] Failed login attempt for user 'admin' from IP 10.0.0.5
... (repeated 100 times in 5 minutes)
2023-11-15 14:28:45 [INFO] Successful login for user 'admin' from IP 10.0.0.5
```

Based on the exhibit, what is the MOST likely risk scenario?

⚠ Common exam trap

ISACA often tests the distinction between authentication failures from a brute force attack versus a denial of service attack, where candidates mistakenly choose DoS because they see many failed attempts, but the key is that the server remains functional and a successful login occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Brute force attack resulting in account compromise

The exhibit shows a high number of failed authentication attempts from a single IP address over a short time window, followed by a successful login. This pattern is characteristic of a brute force attack, where an attacker systematically tries many password combinations until one succeeds, leading to account compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing attack that captured user credentials

    Why it's wrong here

    Credential phishing produces compromised accounts, yet the exhibit's indicators point to repeated authentication failures from an internal source, which phishing would not typically generate. Phishing is tempting because it is the commonest credential-theft vector, and would fit if logs showed successful logins from unfamiliar external addresses.

  • ✓

    Brute force attack resulting in account compromise

    Why this is correct

    Repeated authentication failures against a single account, followed by a successful login, indicate credential guessing rather than malware execution or data exfiltration. The pattern matches brute force leading to account compromise, which is the scenario the exhibit's failed-then-successful logon sequence depicts.

  • ✗

    Insider threat from a legitimate user

    Why it's wrong here

    An insider threat involves a legitimate user abusing granted access, but the exhibit's pattern of failed authentications followed by success points to external credential compromise rather than authorised misuse. Insider threat is tempting because the account is valid, and would fit if the user's own device and normal hours were involved.

  • ✗

    Denial of service attack on the authentication server

    Why it's wrong here

    A denial-of-service attack floods a service to exhaust capacity, whereas the exhibit shows authentication attempts using valid account names, indicating credential misuse rather than volume-based exhaustion. DoS is tempting because authentication servers are frequent targets, and would be correct if the logs showed traffic spikes overwhelming the server.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, which of the following is the MOST likely risk scenario?

easy
  • A.A denial-of-service attack on the SSH service
  • ✓ B.A brute-force attack targeting the root account
  • C.A successful privilege escalation by an insider
  • D.A misconfigured firewall allowing unauthorized access

Why B: The exhibit shows repeated failed login attempts for the root account, which is a classic indicator of a brute-force attack. SSH logs typically record authentication failures, and a high frequency of 'Failed password for root' entries from a single source IP strongly suggests an automated password guessing attempt. This aligns with the risk scenario of a brute-force attack targeting the root account.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.