Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

Which port is used by RDP (Remote Desktop Protocol) and is a common target for brute force attacks?

⚠ Common exam trap

A common mix-up: candidates confuse RDP with other common remote access or web protocols, especially SSH on port 22 or HTTPS on 443, because candidates may associate 'remote' with SSH or 'secure' with 443, overlooking that RDP specifically uses 3389.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

3389

RDP (Remote Desktop Protocol) operates by default on TCP port 3389, a fact that makes it a prime target for brute force attacks because it provides direct interactive access to Windows systems. Attackers frequently scan for open 3389 ports and attempt credential stuffing or password spraying to gain unauthorized remote access. The other ports listed are associated with different services: 443 for HTTPS, 22 for SSH, and 1433 for Microsoft SQL Server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    443

    Why it's wrong here

    Port 443 carries HTTPS traffic; RDP listens on TCP 3389, the port brute-force attacks target. It is tempting because 443 is a familiar remote-access port, and it would be correct for TLS-secured web services, including browser-based remote consoles tunnelled over HTTPS.

  • ✓

    3389

    Why this is correct

    RDP listens on TCP port 3389 by default, so this directly satisfies the stem's requirement. Attackers repeatedly target 3389 with brute force credential attempts because exposed RDP endpoints accept authentication requests, making weak passwords exploitable. Restricting access via Microsoft Entra ID conditional access or a VPN mitigates this exposure.

  • ✗

    22

    Why it's wrong here

    Port 22 carries SSH, which provides encrypted remote shell access on Linux and network devices, not the RDP graphical session service. It is tempting because SSH is also a common brute-force target, but it would be correct only if the question asked which port Secure Shell listens on by default.

  • ✗

    1433

    Why it's wrong here

    Port 1433 carries Microsoft SQL Server's TDS traffic, not RDP, so brute-force attempts against it target database logins rather than Remote Desktop sessions. It is tempting because 1433 is a well-known, frequently attacked service port, but it would be the answer only if the question asked about Microsoft SQL Server's default listening port.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.