Remote Desktop Protocol (RDP)

A proprietary protocol from Microsoft that gives a user the graphical desktop of a remote Windows system, a common remote administration tool and a frequent target when exposed.

The Remote Desktop Protocol (RDP) is a proprietary protocol, developed by Microsoft, that sends a remote system’s screen to the user and returns the user’s keyboard and mouse input. It listens by default on TCP port 3389. Current versions commonly protect the session with TLS, and Network Level Authentication requires the user to authenticate before a full remote session is created, which limits what an unauthenticated caller can reach.

As a remote access tool, RDP falls within the remote access line of the ISC2 exam outline’s Domain 4, and its risk is mostly about exposure. A server reachable from the internet invites password guessing, credential stuffing and exploitation of unpatched flaws, and a successful login gives an interactive foothold on the network. The usual defences are to keep RDP off the internet, reach it only through a VPN or a jump server, require multi-factor authentication, apply account lockout, and patch promptly. RDP is often compared with SSH, which gives an encrypted command-line session rather than a graphical desktop, and with Telnet, which gives a command line with no encryption at all.

Exam relevance: a scenario in which attackers entered through a desktop service left open to the internet is likely to turn on exposed RDP. Candidates are expected to reach for reducing exposure first (a VPN, a jump server, MFA) rather than for encryption, which RDP already has.