hardMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: A security analyst at a mid-sized financial firm
You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the temporary firewall rule that allows RDP from any public IP
The most immediate corrective action is to remove the temporary firewall rule that allows RDP from any public IP. This directly closes the unauthorized access path and mitigates the risk of data exposure. Option B is too broad; disabling RDP on all servers would disrupt legitimate maintenance activities and is not necessary since only one rule is at fault. Option C, while important, is not immediate; conducting a full audit takes time and does not instantly remove the vulnerability. Option D is a long-term preventive measure and does not address the immediate security gap.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Remove the temporary firewall rule that allows RDP from any public IP
Why this is correct
This immediately closes the unauthorized access path.
- ✗
Disable RDP access on all servers
Why it's wrong here
This could disrupt legitimate business operations and is overly broad.
- ✗
Conduct a full audit of all firewall rules
Why it's wrong here
An audit is useful but does not immediately remove the known threat.
- ✗
Implement a security awareness training program for all employees
Why it's wrong here
Training is important but not an immediate corrective action for this specific vulnerability.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.