Courseiva
easyMultiple Choice

ISC2 CC Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.
```
C:\> netstat -an | find "LISTENING"
  TCP    0.0.0.0:80     0.0.0.0:0    LISTENING
  TCP    0.0.0.0:443    0.0.0.0:0    LISTENING
  TCP    192.168.1.10:3389  0.0.0.0:0    LISTENING
```
A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?

Refer to the exhibit. ```

C:\> netstat -an | find "LISTENING"

TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:443 0.0.0.0:0 LISTENING TCP 192.168.1.10:3389 0.0.0.0:0 LISTENING ``` A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?

⚠ Common exam trap

ISC2 often tests the misconception that all listening ports are equally risky, but the trap here is that HTTP and HTTPS are expected services on a server, while RDP is a high-risk administrative service that should be disabled unless explicitly required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remote Desktop (port 3389)

Remote Desktop Protocol (RDP) on port 3389 is a high-risk service that should typically be disabled on servers unless absolutely necessary, as it provides a direct graphical interface for remote administration and is a common target for brute-force attacks. The output shows RDP listening on a specific internal IP (192.168.1.10), indicating it is bound to a routable interface, which increases exposure. In contrast, HTTP (port 80) and HTTPS (port 443) are standard web services that are often required for a server's function, so they are not typically disabled for attack surface reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTP (port 80)

    Why it's wrong here

    Port 80 serves HTTP, the web service the server is deliberately publishing, so disabling it removes required functionality instead of reducing exposure. It is tempting because 80 is unencrypted and externally reachable, but the unnecessary listener in this output is RDP on 3389.

  • ✓

    Remote Desktop (port 3389)

    Why this is correct

    Port 3389 is bound to Remote Desktop Protocol, which permits interactive remote logon and is a frequent target for brute-force and ransomware entry. Disabling it where remote administration is not required removes that exposure, whereas ports 80 and 443 serve expected web traffic.

  • ✗

    All of the above

    Why it's wrong here

    HTTP and HTTPS are commonly required services, so disabling all would likely break functionality.

  • ✗

    HTTPS (port 443)

    Why it's wrong here

    Port 443 carries HTTPS, the encrypted web service the server is meant to expose, so disabling it removes legitimate functionality rather than reducing exposure. It is tempting because 443 is externally reachable, yet the actual unnecessary listener here is RDP on 3389.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.