Courseiva
mediumMultiple Choice

PT0-002 Practice Question: Refer to the exhibit

Exhibit

Active Connections
Proto  Local Address          Foreign Address        State
TCP    10.0.0.15:22          192.168.1.100:54321    ESTABLISHED
TCP    10.0.0.15:80          0.0.0.0:0              LISTENING
TCP    10.0.0.15:443         0.0.0.0:0              LISTENING
TCP    10.0.0.15:3389        203.0.113.50:12345     ESTABLISHED
UDP    10.0.0.15:123         *:*

Refer to the exhibit. A penetration tester obtains this output from a Linux server. The tester notes that port 3389 is typically used for RDP on Windows. Which of the following is the MOST likely explanation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server is running a service that mimics RDP using xrdp

The server is running a service that mimics RDP using xrdp. xrdp is an open-source RDP server for Linux that listens on TCP port 3389, so seeing 3389 open on a Linux host is most likely explained by xrdp providing an RDP-compatible remote desktop service. Option A is speculative and not supported merely by an open port, option B is unlikely without honeypot-specific evidence, and option C is inconsistent because a Windows VM would not make the underlying Linux server itself expose RDP on 3389.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server has been compromised and is used as a jump box

    Why it's wrong here

    Compromise is possible but the exhibit alone does not evidence a jump box; 3389 on Linux commonly indicates xrdp or a forwarded tunnel, and a jump box would typically show outbound sessions or extra listeners. The tempting logic is that RDP-on-Linux implies intrusion, yet legitimate remote-desktop packages explain it without compromise.

  • ✗

    The server is running a honeypot mimicking RDP

    Why it's wrong here

    A honeypot would deliberately expose decoy services, but the stem gives no emulation artefacts such as fake banners, unusual process names or isolated network placement. Honeypots are the right answer when the question asks how to detect or deceive attackers, not to explain a single unexpected listening port on a production host.

  • ✗

    The server is running a Windows virtual machine using RDP

    Why it's wrong here

    Port 3389 is the registered RDP port, but a Linux host listening on it indicates an RDP service such as xrdp, not a Windows guest. The Windows virtual machine explanation is tempting because RDP is native to Windows, yet the exhibit shows the Linux server itself bound to that port.

  • ✓

    The server is running a service that mimics RDP using xrdp

    Why this is correct

    xrdp is an open-source RDP server for Linux that listens on TCP 3389, letting the Linux host accept RDP clients. Its presence explains an RDP-typical port on a non-Windows system, matching the exhibit's Linux output.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.