mediumMultiple Choice
PT0-002 Practice Question: Refer to the exhibit
Exhibit
Active Connections Proto Local Address Foreign Address State TCP 10.0.0.15:22 192.168.1.100:54321 ESTABLISHED TCP 10.0.0.15:80 0.0.0.0:0 LISTENING TCP 10.0.0.15:443 0.0.0.0:0 LISTENING TCP 10.0.0.15:3389 203.0.113.50:12345 ESTABLISHED UDP 10.0.0.15:123 *:*
Refer to the exhibit. A penetration tester obtains this output from a Linux server. The tester notes that port 3389 is typically used for RDP on Windows. Which of the following is the MOST likely explanation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server is running a service that mimics RDP using xrdp
The server is running a service that mimics RDP using xrdp. xrdp is an open-source RDP server for Linux that listens on TCP port 3389, so seeing 3389 open on a Linux host is most likely explained by xrdp providing an RDP-compatible remote desktop service. Option A is speculative and not supported merely by an open port, option B is unlikely without honeypot-specific evidence, and option C is inconsistent because a Windows VM would not make the underlying Linux server itself expose RDP on 3389.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server has been compromised and is used as a jump box
Why it's wrong here
Compromise is possible but the exhibit alone does not evidence a jump box; 3389 on Linux commonly indicates xrdp or a forwarded tunnel, and a jump box would typically show outbound sessions or extra listeners. The tempting logic is that RDP-on-Linux implies intrusion, yet legitimate remote-desktop packages explain it without compromise.
- ✗
The server is running a honeypot mimicking RDP
Why it's wrong here
A honeypot would deliberately expose decoy services, but the stem gives no emulation artefacts such as fake banners, unusual process names or isolated network placement. Honeypots are the right answer when the question asks how to detect or deceive attackers, not to explain a single unexpected listening port on a production host.
- ✗
The server is running a Windows virtual machine using RDP
Why it's wrong here
Port 3389 is the registered RDP port, but a Linux host listening on it indicates an RDP service such as xrdp, not a Windows guest. The Windows virtual machine explanation is tempting because RDP is native to Windows, yet the exhibit shows the Linux server itself bound to that port.
- ✓
The server is running a service that mimics RDP using xrdp
Why this is correct
xrdp is an open-source RDP server for Linux that listens on TCP 3389, letting the Linux host accept RDP clients. Its presence explains an RDP-typical port on a non-Windows system, matching the exhibit's Linux output.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.