CompTIA A+ Core 2 (220-1202)Operational ProceduresHard
An organization allows technicians to remotely support end-user workstations using RDP over the internet. A security audit finds that RDP is exposed directly to the internet on the default port with only username/password authentication. Which change would MOST improve the security of this remote access method?
- ARequire connections to route through a VPN and enable multifactor authentication
- BChange the RDP port to a random high-numbered port only
- CAllow RDP access from any IP address to increase availability
- DDisable Network Level Authentication to simplify connections
Show answer & explanationAnswer & explanation
Correct answer: A. Require connections to route through a VPN and enable multifactor authentication
Exposing RDP directly to the internet is a significant security risk. Requiring a VPN tunnel restricts access to authenticated network members, and adding multifactor authentication greatly reduces the risk of credential-based attacks, providing defense in depth.
Why the other options are wrong
- B. Changing the port only provides minor obscurity and does not address the core exposure risk.
- C. Allowing access from any IP increases the attack surface rather than reducing risk.
- D. Disabling Network Level Authentication actually weakens security, not improves it.
Secure Remote Access
Best practices for remote access security include tunneling protocols like RDP through a VPN, enabling multifactor authentication, and avoiding direct internet exposure of remote access ports.
- Direct internet-facing RDP is a common attack vector
- VPN restricts remote access to authenticated network members
- MFA adds a critical second layer of authentication
Memory trick: Tunnel Through, Then Prove Twice: VPN plus MFA.