Courseiva
hardMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: A security analyst at a mid-sized financial firm

You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove the temporary firewall rule that allows RDP from any public IP

The most immediate corrective action is to remove the temporary firewall rule that allows RDP from any public IP. This directly closes the unauthorized access path and mitigates the risk of data exposure. Option B is too broad; disabling RDP on all servers would disrupt legitimate maintenance activities and is not necessary since only one rule is at fault. Option C, while important, is not immediate; conducting a full audit takes time and does not instantly remove the vulnerability. Option D is a long-term preventive measure and does not address the immediate security gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remove the temporary firewall rule that allows RDP from any public IP

    Why this is correct

    This immediately closes the unauthorized access path.

  • Disable RDP access on all servers

    Why it's wrong here

    This could disrupt legitimate business operations and is overly broad.

  • Conduct a full audit of all firewall rules

    Why it's wrong here

    An audit is useful but does not immediately remove the known threat.

  • Implement a security awareness training program for all employees

    Why it's wrong here

    Training is important but not an immediate corrective action for this specific vulnerability.

About these practice questions

Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.