How to Secure a Publicly Exposed Remote Desktop Host?
A security analyst scans a company's public network and discovers a host is running a remote desktop that can be used to access the production network. Which of the following changes should the security analyst recommend?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to reduce the attack surface of remote access services by leveraging a VPN and firewall-protected jump server rather than relying on obscurity or weak compensating controls.
A publicly exposed remote desktop host increases the attack surface and should be protected by placing it behind a firewall and requiring VPN access. Community consensus strongly supports using a VPN and internal jump server as the best practice for securing remote administrative access.
Option A (changing the RDP port to a non-standard number) is a common wrong answer because candidates confuse security through obscurity with a real defense-in-depth control; port shifting does not prevent authenticated or exploited access.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B recommends placing the remote desktop host behind the firewall and requiring users to connect through a VPN, which effectively eliminates direct public exposure of the RDP service. A VPN enforces authentication and encryption before any traffic reaches the internal network, and the firewall can restrict RDP to only the jump server. This aligns with zero-trust and defense-in-depth principles emphasized in SY0-701.Why the Other Options Are Wrong
Option A (non-standard port) is merely security through obscurity and provides no real protection against scanning or exploitation. Option C (web proxy) only filters HTTP/HTTPS traffic and does nothing to secure RDP sessions. Option D (domain join and longer passwords) improves credential hygiene but still leaves the RDP port exposed to the internet, preserving the original risk.Community Comment Notes
Comment 1 correctly emphasizes that a VPN reduces the attack surface and ensures only authorized users reach the jump server. Comment 2 usefully clarifies why a web proxy is irrelevant to RDP traffic. No comment supported option A, confirming that the community recognizes obscurity as insufficient.Official Reference
Exam Strategy
When a question highlights a service exposed to the public internet, always look for the option that moves the service behind a firewall and adds an authenticated tunnel such as a VPN. Eliminate answers that rely on obscurity, unrelated proxies, or credential changes without addressing exposure.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →