CompTIA A+ Core 2 (220-1202)Operational ProceduresHard

A company's remote employees connect to internal file servers using RDP directly exposed to the internet on port 3389. A security audit recommends reducing this exposure while still allowing remote access. Which solution should be implemented?

  1. ARequire employees to connect through a VPN to establish an encrypted tunnel before using RDP
  2. BAllow RDP access only during standard business hours
  3. CChange the RDP listening port to a random high-numbered port
  4. DDisable RDP authentication prompts to speed up login
Show answer & explanation

Correct answer: A. Require employees to connect through a VPN to establish an encrypted tunnel before using RDP

Requiring a VPN connection before RDP access ensures traffic is encrypted and authenticated at the network layer, greatly reducing the attack surface exposed directly to the internet. Simply changing ports or restricting hours does not eliminate the risk of direct exposure, and disabling authentication would make the system less secure.

Why the other options are wrong

  • B. Time restrictions don't address the fundamental exposure of an open RDP port to the internet.
  • C. Port obscurity does not provide real security and can still be discovered by scanning.
  • D. Disabling authentication prompts removes a critical security control.

VPN for Secure Remote Access

A VPN creates an encrypted tunnel between a remote user and the internal network, reducing the risk of exposing remote access protocols like RDP directly to the internet.

  • VPN should be established before RDP session begins
  • Direct internet-exposed RDP is a common attack vector
  • VPN adds authentication and encryption layers

Memory trick: Tunnel first, then connect — VPN before RDP.

More Operational Procedures questions