220-1102 Operational Procedures Practice Question
A technician needs to provide remote assistance to a user who is not on the corporate network. The technician wants to ensure a secure connection. Which of the following should the technician require the user to do first?
⚠ Common exam trap
The 220-1102 exam often tests the misconception that disabling security controls (like firewalls) is necessary for remote access, when in fact the correct approach is to use a VPN to securely traverse those controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect to the VPN
Connecting to the VPN first establishes an encrypted tunnel between the user's device and the corporate network, ensuring all remote assistance traffic is secured over the public internet. This is the foundational step before initiating any remote desktop or support session, as it authenticates the user and protects data in transit from eavesdropping or tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the software firewall
Why it's wrong here
Disabling the software firewall removes a critical host-based security control that monitors and filters traffic, leaving the endpoint vulnerable to malware and network-based attacks. It does not establish a secure path for remote assistance; rather, it exposes the device during the session. The proper fix is to create firewall rules that allow the VPN's remote assistance traffic while keeping all other filtering active.
- ✓
Connect to the VPN
Why this is correct
A VPN provides an authenticated, encrypted tunnel between the remote user's device and the corporate network, ensuring confidentiality and integrity of the remote assistance session. It allows the helpdesk to reach the user's workstation via internal tools without exposing any services to the public internet. VPN authentication also verifies the user's identity before access is granted, aligning with corporate security policies.
- ✗
Share the user's password
Why it's wrong here
Sharing the user's password violates credential hygiene, removes non-repudiation, and opens the door for unauthorized use and lateral movement. Remote assistance should use session-based authentication or separate support accounts, not the user's personal credentials. A shared password also remains valid after the session, creating a persistent security risk.
- ✗
Enable Remote Desktop directly to the internet
Why it's wrong here
Enabling Remote Desktop directly to the internet exposes port 3389 to attack from any host, inviting brute-force, exploits, and ransomware. There is no encryption or authentication at the network edge, and no protection from NAT or corporate gateway. A VPN or RDP gateway is essential to hide the endpoint and enforce multi-factor authentication.
Go deeper
Related to this question
Learn chapter
Remote Support Tools and Techniques
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.