220-1102 Security Practice Question
A company wants to allow employees to securely access internal resources from home via the internet. Which method provides the highest level of security for remote desktop connections?
⚠ Common exam trap
The trap here is that candidates often mistake security through obscurity (changing the port) for a legitimate security measure, when in fact it does not address the fundamental risk of exposing RDP to the internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require the use of a VPN connection before establishing a Remote Desktop session.
A VPN creates an encrypted tunnel between the remote user and the corporate network, ensuring that all Remote Desktop Protocol (RDP) traffic is protected from eavesdropping and man-in-the-middle attacks. This provides defense-in-depth by first authenticating the user at the VPN layer and then again at the RDP layer, significantly reducing the attack surface compared to exposing RDP directly to the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open port 3389 on the firewall and enable Remote Desktop.
Why it's wrong here
Opening TCP 3389 to the internet publishes the RDP service to every attacker on the planet, enabling continuous port scans, credential brute-forcing, and exploitation of known RDP vulnerabilities such as BlueKeep (CVE-2019-0708). This configuration provides no multi-factor authentication, no device validation, and no network-level access control; it places the full remote desktop session directly on the public attack surface. Even with a strong password, the risk of password spraying or a zero-day exploit is unacceptably high.
- ✗
Configure Remote Desktop to use a non-standard port.
Why it's wrong here
Changing RDP from TCP 3389 to a non-standard port is security through obscurity: modern port scanners can sweep all 65,535 TCP ports in minutes, and protocol fingerprinting tools can identify RDP by its banner regardless of the port number. It does not add encryption beyond RDP's native TLS, does not enforce multi-factor authentication, and does nothing to stop credential-based attacks once the service is found. In practice, it can also break monitoring and firewall rule automation because traffic no longer matches expected signatures.
- ✓
Require the use of a VPN connection before establishing a Remote Desktop session.
Why this is correct
A VPN creates an authenticated, encrypted tunnel (using IPsec or TLS) between the remote user and the internal network, meaning RDP traffic only flows after the user and device have passed authentication and policy checks. The Remote Desktop server can then listen only on an internal interface with no inbound port forwarded from the edge firewall, dramatically shrinking the attack surface. Enterprise configurations often pair the VPN gateway with MFA and endpoint compliance checks, making this the industry-standard way to enable secure remote RDP sessions.
- ✗
Place the remote desktop server in a DMZ with outbound restrictions.
Why it's wrong here
Placing the RDP server in a DMZ with outbound restrictions reduces the blast radius if the server is compromised, because it is network-segmented from internal hosts. However, the RDP service is still directly exposed to the internet: inbound connection attempts reach the server without any VPN, encryption for the session is not enforced by the DMZ, and attackers can brute-force credentials at the perimeter. Outbound restrictions only limit what a compromised server can do after the fact; they do not prevent the initial compromise or mitigate vulnerabilities in the exposed RDP service.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.