220-1102 exam dumps

220-1102 practice question 815 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 815

Single answerSecurity considerations of each access method

A small accounting firm allows employees to work remotely. A technician must recommend the most secure remote access method for staff who need to connect to their office PCs from home over the Internet. The solution must protect credentials and session data from interception and should not expose remote desktop services directly to the public Internet. Which option BEST meets these requirements?

  1. A

    Enable RDP on each office PC and forward TCP port 3389 from the firewall to the appropriate workstation

  2. B

    Require users to connect to the company VPN first, and then access their office PCs using Remote Desktop over the VPN tunnel

  3. C

    Use Telnet to access office systems because it uses fewer resources than encrypted remote access methods

  4. D

    Use FTP with individual user accounts so employees can remotely control their office PCs without opening remote desktop ports

Show answer and explanation

Correct answer: B

Explanation

The best answer is to require users to connect through a VPN and then use Remote Desktop internally. In A+ Core 2, a key security consideration of access methods is understanding which methods encrypt traffic and which ones unnecessarily expose services. VPNs are designed to create encrypted tunnels across untrusted networks, making them a preferred way to reach internal resources remotely. By contrast, opening RDP directly to the Internet increases risk even if the protocol itself supports encryption, because the service becomes publicly reachable and attackable. Telnet is insecure because it does not encrypt sessions, and FTP is not a remote control solution. Best-practice guidance from Microsoft and general security frameworks consistently recommends limiting public exposure of administrative services, using encrypted remote access methods, and applying least exposure by requiring secure network access first.

  • A. Incorrect.

    This is incorrect because exposing RDP directly to the Internet by forwarding TCP 3389 significantly increases attack surface. Remote Desktop is commonly targeted by brute-force attacks, credential stuffing, and exploitation attempts. While RDP can be secured with strong passwords, account lockout policies, and Network Level Authentication, best practice is to avoid publishing it directly when a VPN can provide a protected access path first.

  • B. Correct.

    This is correct because a VPN encrypts traffic between the remote user and the company network before the Remote Desktop session starts. That helps protect credentials and session data in transit and reduces exposure by keeping RDP off the public Internet. This layered approach aligns with common security best practices for remote access: establish a secure tunnel first, then access internal services.

  • C. Incorrect.

    This is incorrect because Telnet is not appropriate for secure remote access. Telnet transmits data, including credentials, in cleartext, making it vulnerable to interception on untrusted networks. A candidate might choose this option if they confuse simple connectivity with secure connectivity, but Telnet is specifically a poor choice for Internet-based administrative access.

  • D. Incorrect.

    This is incorrect because FTP is a file transfer protocol, not a remote desktop control method. Standard FTP also does not provide secure encryption for credentials and data unless replaced with a secure alternative such as FTPS or SFTP, and even then it would not solve the need for interactive remote control of office PCs. This distractor targets the misconception that any authenticated remote service is suitable for desktop access.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam