mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: Refer to the exhibit
Exhibit
Feb 15 09:23:45 fw01 %ASA-4-722041: Tunnel negotiation failed to/from IP 203.0.113.5 to 198.51.100.20 due to authentication failure. Feb 15 09:24:12 fw01 %ASA-4-722041: Tunnel negotiation failed to/from IP 203.0.113.5 to 198.51.100.20 due to authentication failure. Feb 15 09:24:50 fw01 %ASA-4-722041: Tunnel negotiation failed to/from IP 203.0.113.5 to 198.51.100.20 due to authentication failure.
Refer to the exhibit. A security analyst reviews firewall logs and sees repeated authentication failures for VPN tunnel attempts between two IP addresses. What is the MOST appropriate action?
⚠ Common exam trap
A common mix-up: candidates choose Option B (contacting the destination IP owner) because they assume a credential issue, but the question emphasizes repeated failures from a single source IP, which is a classic sign of an attack requiring immediate blocking, not administrative coordination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the source IP (203.0.113.5) at the firewall.
Repeated authentication failures for VPN tunnel attempts between two IP addresses indicate a potential brute-force attack or misconfigured credentials. Blocking the source IP (203.0.113.5) at the firewall is the most appropriate immediate action to mitigate the threat, as it stops further attempts without disrupting legitimate traffic. This aligns with the CRISC domain of Risk and Control Monitoring and Reporting, where timely response to anomalous events is critical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block the source IP (203.0.113.5) at the firewall.
Why this is correct
Blocking the attacking IP mitigates threat.
- ✗
Contact the destination IP owner to verify credentials.
Why it's wrong here
Source is likely the attacker.
- ✗
Update the VPN policy to allow all authentication methods.
Why it's wrong here
Not addressing root cause.
- ✗
Ignore the logs as routine failed attempts.
Why it's wrong here
Repeated failures warrant action.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.