Security Considerations for Remote Access Methods for A+
Short answer
Every remote access method introduces potential exposure. Technicians should verify the identity of the requestor, prefer encrypted channels (SSH, SFTP, RDP over TLS, VPN), limit privileges to only what is necessary, obtain explicit user consent for remote control, and ensure sessions are logged when required. If a method lacks encryption or strong authentication, avoid it for sensitive tasks or use a secure tunnel.
Why it appears on the exam
- Given a scenario, select the more secure option (SFTP vs. FTP, VPN+RDP vs. RDP over open internet) and explain why. - Identify required consent or logging actions for a given support session.
Key concepts
Concept 1
Required terms
Authentication: Verifying the identity of a user or system before granting access; may include passwords, multi-factor authentication, or certificates. Encryption: Protecting data in transit so that eavesdroppers cannot read it; relevant when selecting remote methods (e.g., SSH, SFTP, VPN provide encryption). User consent: Explicit permission by the device owner/user before allowing remote control or elevated access; important for privacy and compliance. Authentication: verify identity before access.
Example
Refuse to accept plain FTP for transferring sensitive logs; use SFTP instead.
Concept 2
How Security Considerations for Remote Access Methods works
Every remote access method introduces potential exposure. Technicians should verify the identity of the requestor, prefer encrypted channels (SSH, SFTP, RDP over TLS, VPN), limit privileges to only what is necessary, obtain explicit user consent for remote control, and ensure sessions are logged when required. If a method lacks encryption or strong authentication, avoid it for sensitive tasks or use a secure tunnel.
Example
Before initiating a remote-control session via third-party tool, confirm the user explicitly grants control and document the session.
Concept 3
Common confusion
Technicians may prioritize convenience over security (e.g., using an unencrypted tool for a quick transfer). Emphasize that quick convenience can create compliance or security incidents.
Example
If an RMM alerts to a critical update, verify authentication and schedule an approved maintenance window rather than performing unscheduled intrusive actions.
Concept 4
Core 2 (220-1202) question cues
Given a scenario, select the more secure option (SFTP vs. FTP, VPN+RDP vs. RDP over open internet) and explain why; Identify required consent or logging actions for a given support session.
Example
Refuse to accept plain FTP for transferring sensitive logs; use SFTP instead.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A technician is troubleshooting this situation: If an RMM alerts to a critical update, verify authentication and schedule an approved maintenance window rather than performing unscheduled intrusive actions. What should they identify?
Q2.A technician sees this situation: Before initiating a remote-control session via third-party tool, confirm the user explicitly grants control and document the session. Which answer should they choose?
Q3.Read this A+ scenario: If an RMM alerts to a critical update, verify authentication and schedule an approved maintenance window rather than performing unscheduled intrusive actions. Which term or action matches it?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8