ISC2 CC Security Operations Practice Question
A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?
⚠ Common exam trap
The trap here is opting for a mitigation like firewall rules or port changes instead of eliminating the unnecessary service, which is the most effective way to reduce attack surface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the Remote Desktop Protocol service if it is not required for administration
The first step in reducing attack surface is to remove unnecessary services. Since port 3389 is open due to RDP, and if RDP is not required, disabling it eliminates the exposure entirely. Other measures like firewall restrictions or authentication enhancements are useful but secondary to removing the service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Network Level Authentication for RDP connections
Why it's wrong here
Network Level Authentication adds an authentication layer before a session is established, which is a good security practice. However, it does not remove the open port or the service. If RDP is not needed, disabling it is a more fundamental risk reduction.
- ✗
Configure the firewall to allow RDP only from specific IP addresses
Why it's wrong here
Restricting RDP access to specific IPs reduces risk but does not eliminate the open port. The service remains running and could be exploited if an attacker gains access to an allowed IP or if there is a vulnerability. Disabling the service is a stronger first step when RDP is not required.
- ✗
Change the RDP listening port to a non-standard number
Why it's wrong here
Changing the port number provides minimal security through obscurity. Attackers can easily scan for RDP on other ports, and the service remains vulnerable. This does not reduce the attack surface effectively and may complicate legitimate administration.
- ✓
Disable the Remote Desktop Protocol service if it is not required for administration
Why this is correct
Port 3389 is used by Remote Desktop Protocol (RDP). If RDP is not needed, disabling the service closes the port and eliminates a common attack vector. This is the most direct and effective step to reduce the attack surface, as it removes the service entirely rather than just restricting access.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.