mediumMultiple ChoiceObjective-mapped
220-1202 Practice Question: During a security audit, a technician discovers…
During a security audit, a technician discovers that an employee has been using a third-party remote desktop tool without IT approval. The employee claims it was necessary to access a legacy application. Which security risk is most directly associated with unauthorized remote access tools?
⚠ Common exam trap
CompTIA often tests the distinction between operational issues (bandwidth, compatibility, cost) and actual security threats, so candidates mistakenly choose a non-security answer like increased bandwidth usage because it sounds like a plausible downside of remote access tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Man-in-the-middle attacks
Unauthorized remote desktop tools often lack the encryption and authentication controls found in approved solutions like SSH or RDP with Network Level Authentication. This exposes the connection to man-in-the-middle attacks, where an attacker can intercept, decrypt, or modify the traffic between the employee's workstation and the legacy application server, potentially capturing credentials or sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increased bandwidth usage
Why it's wrong here
Increased bandwidth usage primarily indicates a performance or operational issue, such as inefficient data transfer, large file synchronization, or even legitimate high-volume network traffic. While a sudden, unexplained spike in bandwidth could be a symptom of a security breach, like data exfiltration or botnet activity, the usage itself is not a direct security risk. It does not inherently compromise data confidentiality, integrity, or availability; rather, it's an indicator that warrants further investigation into potential underlying causes, which could be security-related.
- ✓
Man-in-the-middle attacks
Why this is correct
Unauthorized tools, especially those not properly vetted or configured, often lack robust security features such as strong encryption protocols (e.g., TLS 1.3) or proper certificate validation. This deficiency creates vulnerabilities where an attacker can intercept communications between two parties, read sensitive data, or even alter messages in transit without either party being aware. Such tools provide an ideal vector for man-in-the-middle attacks, directly compromising the confidentiality and integrity of data exchanged and potentially leading to unauthorized access or system manipulation.
- ✗
Compatibility issues with the operating system
Why it's wrong here
Compatibility issues with the operating system typically manifest as software malfunctions, system instability, or inability for an application to run correctly. These are operational and technical challenges that hinder functionality and productivity, requiring troubleshooting or alternative solutions. While an incompatible application might fail to receive security updates or create system instability that could indirectly lead to a vulnerability if not addressed, the incompatibility itself is not a direct security risk that actively compromises data or system integrity.
- ✗
Increased licensing costs
Why it's wrong here
Increased licensing costs represent a financial and budgetary concern for an organization, impacting operational expenses and resource allocation. This issue pertains to the economic management of software assets and compliance with vendor agreements, rather than the security posture of the system or data. While unauthorized software might bypass licensing, leading to legal or financial penalties, the cost itself does not directly introduce vulnerabilities, facilitate attacks, or compromise the confidentiality, integrity, or availability of information.
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.