Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company wants to allow employees to securely access internal resources from home via the internet. Which method provides the highest level of security for remote desktop connections?

⚠ Common exam trap

The trap here is that candidates often mistake security through obscurity (changing the port) for a legitimate security measure, when in fact it does not address the fundamental risk of exposing RDP to the internet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require the use of a VPN connection before establishing a Remote Desktop session.

A VPN creates an encrypted tunnel between the remote user and the corporate network, ensuring that all Remote Desktop Protocol (RDP) traffic is protected from eavesdropping and man-in-the-middle attacks. This provides defense-in-depth by first authenticating the user at the VPN layer and then again at the RDP layer, significantly reducing the attack surface compared to exposing RDP directly to the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Open port 3389 on the firewall and enable Remote Desktop.

    Why it's wrong here

    Opening TCP 3389 to the internet publishes the RDP service to every attacker on the planet, enabling continuous port scans, credential brute-forcing, and exploitation of known RDP vulnerabilities such as BlueKeep (CVE-2019-0708). This configuration provides no multi-factor authentication, no device validation, and no network-level access control; it places the full remote desktop session directly on the public attack surface. Even with a strong password, the risk of password spraying or a zero-day exploit is unacceptably high.

  • ✗

    Configure Remote Desktop to use a non-standard port.

    Why it's wrong here

    Changing RDP from TCP 3389 to a non-standard port is security through obscurity: modern port scanners can sweep all 65,535 TCP ports in minutes, and protocol fingerprinting tools can identify RDP by its banner regardless of the port number. It does not add encryption beyond RDP's native TLS, does not enforce multi-factor authentication, and does nothing to stop credential-based attacks once the service is found. In practice, it can also break monitoring and firewall rule automation because traffic no longer matches expected signatures.

  • ✓

    Require the use of a VPN connection before establishing a Remote Desktop session.

    Why this is correct

    A VPN creates an authenticated, encrypted tunnel (using IPsec or TLS) between the remote user and the internal network, meaning RDP traffic only flows after the user and device have passed authentication and policy checks. The Remote Desktop server can then listen only on an internal interface with no inbound port forwarded from the edge firewall, dramatically shrinking the attack surface. Enterprise configurations often pair the VPN gateway with MFA and endpoint compliance checks, making this the industry-standard way to enable secure remote RDP sessions.

  • ✗

    Place the remote desktop server in a DMZ with outbound restrictions.

    Why it's wrong here

    Placing the RDP server in a DMZ with outbound restrictions reduces the blast radius if the server is compromised, because it is network-segmented from internal hosts. However, the RDP service is still directly exposed to the internet: inbound connection attempts reach the server without any VPN, encryption for the session is not enforced by the DMZ, and attackers can brute-force credentials at the perimeter. Outbound restrictions only limit what a compromised server can do after the fact; they do not prevent the initial compromise or mitigate vulnerabilities in the exposed RDP service.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.