Soru

Zorluk: ZorRemote Access Technologies and Tools

A network security analyst is auditing remote management configurations for a fleet of off-site Windows 11 workstations used by remote employees. To enable centralized, secure administrative access for unattended maintenance over public networks, which of the following requirements must be met on the target workstations and network perimeter? (Select TWO.)

  1. The target workstations must run Windows 11 Pro or Enterprise edition.Cevap
  2. The connection must be established through a Virtual Private Network (VPN) tunnel or secure gateway before initiating RDP traffic.Cevap
  3. C
    The network perimeter firewall must open inbound TCP port 23 to handle encrypted session handshakes.
  4. D
    Remote Assistance (MSRA) must be configured in unattended mode to listen on TCP port 22.

Cevap

The target workstations must run Windows 11 Pro or Enterprise edition, and the connection must be established through a Virtual Private Network (VPN) tunnel or secure gateway prior to initiating RDP traffic.
To securely enable unattended remote administration using Windows Remote Desktop, the target host operating system must support RDP hosting (which requires Windows Pro, Enterprise, or Education editions). Additionally, because direct exposure of RDP over the internet is insecure, access must be secured behind a VPN tunnel or secure remote access gateway.

Adım Adım Çözüm

1
Analyze operating system hosting requirements for incoming Remote Desktop connections.
Identify that Windows Home editions lack the Remote Desktop host capability, requiring Pro or Enterprise editions.
CompTIA OS feature standards reserve incoming RDP server capabilities for business-class OS editions.
2
Evaluate network security protocol best practices for remote access across untrusted networks.
Determine that raw RDP port exposure to the public internet should be avoided in favor of an encrypted VPN tunnel or RD Gateway.
Directly exposing port 3389 to the internet invites brute-force attacks and protocol exploitation.
3
Verify correct ports and protocols for remote administration.
Confirm RDP uses TCP port 3389 (not port 22 or port 23).
TCP port 22 is used by SSH and TCP port 23 is unencrypted Telnet.

Anahtar Kavram

Remote Access Protocols, Windows Edition Restrictions, and Security Best Practices
Bu soruyu puanla