Courseiva
hardMultiple Choice

220-1102 Practice Question: During a routine security scan, a technician…

During a routine security scan, a technician finds that a user's workstation has an open port 3389 that is accessible from the internet. The user denies enabling Remote Desktop. What is the most likely security implication and immediate action?

⚠ Common exam trap

CompTIA A+ exams often test the misconception that changing a default port or enabling additional authentication is sufficient to secure an exposed service, when the correct immediate action is to close the port and disable the service entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the Remote Desktop service and block port 3389 at the firewall immediately.

Port 3389 is the default port for Remote Desktop Protocol (RDP). An open RDP port accessible from the internet is a critical security risk because it exposes the workstation to brute-force attacks, credential theft, and remote exploitation (e.g., BlueKeep, CVE-2019-0708). The immediate action is to disable the Remote Desktop service and block port 3389 at the firewall, as the user denies enabling it, indicating possible unauthorized activation or malware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The port is likely used by a legitimate application; no action is needed.

    Why it's wrong here

    Port 3389 is RDP, and internet exposure with the user denying Remote Desktop indicates unauthorised remote-access software or a backdoor, requiring immediate blocking and investigation. It is tempting because some legitimate applications do bind high ports, and taking no action is correct only after confirming the listener is expected and firewalled.

  • ✓

    Disable the Remote Desktop service and block port 3389 at the firewall immediately.

    Why this is correct

    An internet-reachable port 3389 indicates Remote Desktop was enabled, possibly by malware or unauthorised configuration, exposing the workstation to brute-force and exploitation. Disabling the service and blocking the port at the firewall immediately removes that exposure.

  • ✗

    Change the RDP listening port to a non-standard port to hide it.

    Why it's wrong here

    Changing the RDP listening port only obscures the service; port 3389 exposed to the internet still signals RDP is enabled, and scanners detect non-standard ports anyway. It is tempting because port obfuscation reduces automated scan noise, but it would suit hardening a deliberately internet-facing RDP host, not closing an unauthorised listener.

  • ✗

    Enable Network Level Authentication (NLA) on the workstation.

    Why it's wrong here

    NLA hardens authentication but leaves the RDP listener exposed to the internet, so the unauthorised remote-access path remains open; the port must be blocked or RDP disabled. It is tempting because NLA genuinely mitigates RDP attacks, and it is the correct hardening step once remote access is deliberately required and firewalled.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.