How to Secure a Publicly Exposed Remote Desktop Host?

A security analyst scans a company's public network and discovers a host is running a remote desktop that can be used to access the production network. Which of the following changes should the security analyst recommend?

  1. Changing the remote desktop port to a non-standard number
  2. Setting up a VPN and placing the jump server inside the firewall Source Reference Answer
  3. Using a proxy for web connections from the remote desktop server
  4. Connecting the remote server to the domain and increasing the password length

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to reduce the attack surface of remote access services by leveraging a VPN and firewall-protected jump server rather than relying on obscurity or weak compensating controls.

A publicly exposed remote desktop host increases the attack surface and should be protected by placing it behind a firewall and requiring VPN access. Community consensus strongly supports using a VPN and internal jump server as the best practice for securing remote administrative access.

Option A (changing the RDP port to a non-standard number) is a common wrong answer because candidates confuse security through obscurity with a real defense-in-depth control; port shifting does not prevent authenticated or exploited access.

Community Discussion (5 comments)

dbrowndiver 👍 8 Selected: B
Setting up a VPN and placing the jump server inside the firewall is the most secure approach because it reduces the attack surface and ensures that only authorized users can access the remote desktop service. This solution addresses the primary security concern of protecting sensitive production systems by ensuring that only verified users can gain access, thus minimizing the attack surface and potential vulnerabilities.
9149f41 👍 2 Selected: B
Why C is correct: The issue is relevant with a remote server, not a web application. A proxy for web connections would only secure web traffic, not the remote desktop protocol (RDP) traffic. RD, as well as any server or computer connection, are designed as a VPN, not a proxy.
MaxiPrince 👍 1 Selected: B
Setting up a VPN and placing the jump server inside the firewall
Shaman73 👍 2 Selected: B
B. Setting up a VPN and placing the jump server inside the firewall
MahiMahiMahi 👍 2 Selected: B
B. Setting up a VPN and placing the jump server inside the firewall

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B recommends placing the remote desktop host behind the firewall and requiring users to connect through a VPN, which effectively eliminates direct public exposure of the RDP service. A VPN enforces authentication and encryption before any traffic reaches the internal network, and the firewall can restrict RDP to only the jump server. This aligns with zero-trust and defense-in-depth principles emphasized in SY0-701.

Why the Other Options Are Wrong

Option A (non-standard port) is merely security through obscurity and provides no real protection against scanning or exploitation. Option C (web proxy) only filters HTTP/HTTPS traffic and does nothing to secure RDP sessions. Option D (domain join and longer passwords) improves credential hygiene but still leaves the RDP port exposed to the internet, preserving the original risk.

Community Comment Notes

Comment 1 correctly emphasizes that a VPN reduces the attack surface and ensures only authorized users reach the jump server. Comment 2 usefully clarifies why a web proxy is irrelevant to RDP traffic. No comment supported option A, confirming that the community recognizes obscurity as insufficient.

Official Reference

Exam Strategy

When a question highlights a service exposed to the public internet, always look for the option that moves the service behind a firewall and adds an authenticated tunnel such as a VPN. Eliminate answers that rely on obscurity, unrelated proxies, or credential changes without addressing exposure.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide