A security analyst scans a company's public network and discovers a host is running a remote desktop that can be used to access the production network. Which of the following changes should the security analyst recommend?
Choose an answer
Tap an option to check your answer.
Correct answer: Setting up a VPN and placing the jump server inside the firewall.
Why this is the answer
Setting up a VPN and placing the jump server inside the firewall is the most secure recommendation. A VPN encrypts the connection and requires authentication, preventing unauthorized access to the remote desktop. Placing the jump server inside the firewall ensures it is protected by the organization's perimeter defenses, limiting direct exposure to the public internet. Changing the remote desktop port to a non-standard number offers only a minor security improvement, as port scanning can easily discover open ports. Using a proxy for web connections from the remote desktop server does not address the fundamental security risk of an exposed remote desktop service. Connecting the remote server to the domain and increasing password length are good security practices but do not mitigate the risk of an unauthenticated, unencrypted remote desktop service being directly accessible from the public network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed