Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the access control list (ACL) on a router that connects the corporate network to the internet. The auditor notices that the ACL permits inbound traffic on port 3389 (RDP) from any source IP address to a specific internal server. Which of the following is the MOST appropriate recommendation?

⚠ Common exam trap

The trap here is choosing a hardening measure like changing the port or enabling NLA, which does not address the core problem of unrestricted inbound access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict inbound RDP access to specific trusted IP addresses or require VPN access.

The most appropriate recommendation is to restrict inbound RDP access to specific trusted IP addresses or require VPN access. This directly reduces the exposure of the RDP service to potential attackers. While other measures like NLA or account lockout can add defense in depth, they do not address the fundamental issue of allowing RDP from any source. Restricting access is a preventive control that aligns with least privilege and reduces the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement account lockout policies to prevent brute-force attacks.

    Why it's wrong here

    Account lockout policies can help mitigate brute-force attacks, but they can also lead to denial of service if an attacker intentionally locks out accounts. Moreover, they do not address the exposure of RDP to the entire internet. The server is still vulnerable to other attacks, such as those exploiting RDP vulnerabilities. The most effective control is to restrict access to the service, not just to harden authentication.

  • ✗

    Change the default RDP port to a non-standard port to obscure the service.

    Why it's wrong here

    Changing the default port is a form of security through obscurity and does not provide real protection. Attackers can easily scan for RDP on other ports. It may reduce automated scans but does not address the fundamental issue of unrestricted access. The best practice is to restrict access by IP or use a VPN, not to rely on port obfuscation.

  • ✗

    Enable Network Level Authentication (NLA) on the RDP server.

    Why it's wrong here

    NLA is a good security measure that requires authentication before a session is established, but it does not prevent the server from being exposed to the internet. Attackers can still attempt to authenticate, and vulnerabilities may exist. While NLA should be enabled, it is not sufficient to mitigate the risk of unrestricted inbound RDP. The primary recommendation should be to restrict access.

  • ✓

    Restrict inbound RDP access to specific trusted IP addresses or require VPN access.

    Why this is correct

    Allowing RDP from any source IP exposes the server to brute-force attacks, credential stuffing, and exploitation of RDP vulnerabilities. The most appropriate recommendation is to restrict access to known trusted IPs or require users to connect via VPN, which adds an authentication layer. This reduces the attack surface and aligns with the principle of least privilege. It directly addresses the risk of unauthorized access.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.