Courseiva
Security Operations →mediumMultiple Choice

ISC2 CC Security Operations Practice Question

A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?

⚠ Common exam trap

The trap here is assuming that any repeated connection attempts constitute a DoS attack, but the specific targeting of port 3389 points to RDP brute force rather than volumetric flooding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remote Desktop Protocol (RDP) brute force

TCP port 3389 is the default port for Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses indicate an RDP brute-force attack, where attackers try to guess credentials to gain remote access. This is a common and dangerous attack, as successful compromise can lead to full system control. Other attack types do not match the described network behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denial-of-service (DoS) attack

    Why it's wrong here

    A DoS attack aims to overwhelm a service with traffic, causing it to become unavailable. While repeated connection attempts could contribute to resource exhaustion, the scenario specifically mentions multiple external IP addresses targeting port 3389, which is more indicative of a brute-force attempt to gain access rather than a volumetric DoS. DoS typically involves a flood of traffic to many ports or a specific service, not just connection attempts.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection targets web applications by inserting malicious SQL queries through input fields. It does not involve direct connection attempts to TCP port 3389. The scenario describes network-level connection attempts to an RDP port, which is unrelated to SQL injection. SQL injection would be detected in web server logs or application logs, not firewall logs showing port 3389 traffic.

  • ✓

    Remote Desktop Protocol (RDP) brute force

    Why this is correct

    TCP port 3389 is used by Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses suggest a brute-force attack attempting to guess credentials for RDP access. This is a common attack vector for gaining unauthorized remote access to Windows systems. Monitoring and blocking such attempts is critical to prevent compromise.

  • ✗

    Ransomware encryption

    Why it's wrong here

    Ransomware encryption is a post-compromise activity that encrypts files on a system. The scenario describes inbound connection attempts to a specific port, which indicates scanning or exploitation attempts, not active encryption. Ransomware would typically generate outbound traffic or file system events, not repeated inbound connections to port 3389.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.