Which remote access model best reduces attacks from connecting devices?
Which of the following is the MOST effective remote access model for reducing the likelihood of attacks originating from connecting devices?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the principle of reducing endpoint attack surface; the trap is confusing network-level security (VPNs) with endpoint-level risk reduction, where thin clients excel.
For the CDPSE exam, the most effective remote access model to reduce attacks originating from connecting devices is thin client RDP, not a site-to-site VPN. Thin clients minimize endpoint attack surface by keeping data and processing on the server, and community discussion supports this security advantage.
Choosing C, Site-to-site VPN, because VPNs are heavily associated with secure remote access. However, a site-to-site VPN only secures network communications and does not protect against attacks originating from compromised connecting devices, unlike a thin client that removes sensitive data and processing from the endpoint.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B, Thin client remote desktop protocol (RDP), is the most effective model because thin clients drastically reduce the attack surface of connecting devices. Sensitive data and applications remain on the centralized server, so even if a thin client endpoint is compromised, the attacker gains no direct access to stored data and cannot introduce malware into the corporate network through the endpoint. This architecture directly addresses the likelihood of attacks originating from devices themselves by making those devices less valuable and less capable targets.
Why the Other Options Are Wrong
A, Remote WAN links, simply extends the network and offers no endpoint security features, leaving connecting devices fully vulnerable. C, Site-to-site VPN, is a network-level security control that protects data in transit but does not reduce the risk of attacks originating from compromised endpoints on either side of the VPN. D, Thick client desktop with VPN, actually increases endpoint attack surface because the device stores data and runs full applications, even though the VPN secures the communication channel.
Community Comment Notes
The most useful comment [1] correctly explains that thin clients are generally more secure than thick clients because they minimize data and application processing on the endpoint, and compromise impact is limited. The votes showing 100% for C appear inconsistent with this reasoning, and the comment strongly suggests B is the intended answer. Comment [2] merely states C without justification and should be weighed against the architectural reasoning provided in the higher-quality comment.
Official Reference
Exam Strategy
When asked about the 'most effective' remote access model to reduce attacks from connecting devices, focus on endpoint attack surface, not just encryption. Thin client and other centralized computing models are almost always correct because they remove data and processing from the remote device, unlike VPN-only solutions.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →