Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: Refer to the exhibit

Exhibit

Firewall log:
2025-03-15 14:23:45 src=10.0.1.100 dst=192.168.2.50 port=3389 action=deny

Refer to the exhibit. What risk is most directly indicated by this log entry?

⚠ Common exam trap

The trap is that candidates may think an internal IP indicates an insider threat (Option D), but the question asks for the risk 'most directly indicated' — which is the specific unauthorized access attempt. The internal IPs do not automatically imply malicious internal users; they could indicate compromised devices or misconfigurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Unauthorized access attempt

The log entry shows repeated failed login attempts via RDP from internal IP addresses (10.0.1.100 and 192.168.2.50). This pattern directly indicates an unauthorized access attempt, as someone is trying to gain access using incorrect credentials. It is not an external attack because the source IPs are internal, not a misconfigured firewall because the traffic is allowed but authentication fails, and not definitively an insider threat as the source could be a compromised system. The most direct risk is the unauthorized access attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • External attack

    Why it's wrong here

    Both source and destination are internal IPs (10.0.1.100 and 192.168.2.50), so not external.

  • Misconfigured firewall

    Why it's wrong here

    The rule denied the traffic, so it is functioning as configured; misconfiguration would allow it.

  • Unauthorized access attempt

    Why this is correct

    An internal device attempting RDP to another internal device without apparent authorization indicates a potential unauthorized access attempt.

  • Insider threat

    Why it's wrong here

    While possible, the log alone does not confirm malicious intent; it indicates an attempt.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.