ISC2 CC Security Operations Practice Question
A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?
⚠ Common exam trap
The trap here is assuming that any repeated connection attempts constitute a DoS attack, but the specific targeting of port 3389 points to RDP brute force rather than volumetric flooding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remote Desktop Protocol (RDP) brute force
TCP port 3389 is the default port for Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses indicate an RDP brute-force attack, where attackers try to guess credentials to gain remote access. This is a common and dangerous attack, as successful compromise can lead to full system control. Other attack types do not match the described network behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denial-of-service (DoS) attack
Why it's wrong here
A DoS attack aims to overwhelm a service with traffic, causing it to become unavailable. While repeated connection attempts could contribute to resource exhaustion, the scenario specifically mentions multiple external IP addresses targeting port 3389, which is more indicative of a brute-force attempt to gain access rather than a volumetric DoS. DoS typically involves a flood of traffic to many ports or a specific service, not just connection attempts.
- ✗
SQL injection
Why it's wrong here
SQL injection targets web applications by inserting malicious SQL queries through input fields. It does not involve direct connection attempts to TCP port 3389. The scenario describes network-level connection attempts to an RDP port, which is unrelated to SQL injection. SQL injection would be detected in web server logs or application logs, not firewall logs showing port 3389 traffic.
- ✓
Remote Desktop Protocol (RDP) brute force
Why this is correct
TCP port 3389 is used by Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses suggest a brute-force attack attempting to guess credentials for RDP access. This is a common attack vector for gaining unauthorized remote access to Windows systems. Monitoring and blocking such attempts is critical to prevent compromise.
- ✗
Ransomware encryption
Why it's wrong here
Ransomware encryption is a post-compromise activity that encrypts files on a system. The scenario describes inbound connection attempts to a specific port, which indicates scanning or exploitation attempts, not active encryption. Ransomware would typically generate outbound traffic or file system events, not repeated inbound connections to port 3389.
Visual reference
Go deeper
Related to this question
Learn chapter
Wireless and Remote Access Security
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.