ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 177 - CAS-004 discussion

Report
Export

A security architect was asked to modify an existing internal network design to accommodate the following requirements for RDP:

* Enforce MFA for RDP

* Ensure RDP connections are only allowed with secure ciphers.

The existing network is extremely complex and not well segmented. Because of these limitations, the company has requested that the connections not be restricted by network-level firewalls Of ACLs.

Which of the following should the security architect recommend to meet these requirements?

A.
Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
Answers
A.
Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
B.
Implement a bastion host with a secure cipher configuration enforced.
Answers
B.
Implement a bastion host with a secure cipher configuration enforced.
C.
Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP
Answers
C.
Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP
D.
Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
Answers
D.
Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
Suggested answer: C

Explanation:

A remote desktop gateway server is a solution that allows users to connect to remote desktops or applications over the internet using the Remote Desktop Protocol (RDP). A remote desktop gateway server can enforce MFA for RDP by integrating with Azure AD MFA using the Network Policy Server (NPS) extension. The NPS extension can send an OTP (one-time password) to the user's phone or mobile app as a second factor of authentication. A remote desktop gateway server can also enforce secure ciphers by configuring the SSL Cipher Suite Order Group Policy setting to specify the preferred order of cipher suites for TLS/SSL connections. Verified

Reference:

https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-plan-access-from-anywhere

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-rdg

https://docs.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings#ssl-cipher-suite-order

asked 02/10/2024
Oscar Ballabriga
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first