Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: Refer to the exhibit

Exhibit

Feb 15 09:23:45 fw01 %ASA-4-722041: Tunnel negotiation failed to/from IP 203.0.113.5 to 198.51.100.20 due to authentication failure.
Feb 15 09:24:12 fw01 %ASA-4-722041: Tunnel negotiation failed to/from IP 203.0.113.5 to 198.51.100.20 due to authentication failure.
Feb 15 09:24:50 fw01 %ASA-4-722041: Tunnel negotiation failed to/from IP 203.0.113.5 to 198.51.100.20 due to authentication failure.

Refer to the exhibit. A security analyst reviews firewall logs and sees repeated authentication failures for VPN tunnel attempts between two IP addresses. What is the MOST appropriate action?

⚠ Common exam trap

A common mix-up: candidates choose Option B (contacting the destination IP owner) because they assume a credential issue, but the question emphasizes repeated failures from a single source IP, which is a classic sign of an attack requiring immediate blocking, not administrative coordination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Block the source IP (203.0.113.5) at the firewall.

Repeated authentication failures for VPN tunnel attempts between two IP addresses indicate a potential brute-force attack or misconfigured credentials. Blocking the source IP (203.0.113.5) at the firewall is the most appropriate immediate action to mitigate the threat, as it stops further attempts without disrupting legitimate traffic. This aligns with the CRISC domain of Risk and Control Monitoring and Reporting, where timely response to anomalous events is critical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block the source IP (203.0.113.5) at the firewall.

    Why this is correct

    Blocking the attacking IP mitigates threat.

  • Contact the destination IP owner to verify credentials.

    Why it's wrong here

    Source is likely the attacker.

  • Update the VPN policy to allow all authentication methods.

    Why it's wrong here

    Not addressing root cause.

  • Ignore the logs as routine failed attempts.

    Why it's wrong here

    Repeated failures warrant action.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.