During a penetration test, an assessor attempts to remotely access a Remote Desktop service exposed in a screened subnet (DMZ) from the internet. The tester learns that the organization intends to allow RDP (Remote Desktop Protocol) access only from a single trusted external IP address belonging to the Chief Security Officer’s home network. The network segmentation is configured as follows:
Untrusted (Internet) 143.27.43.0/24, DMZ 161.212.71.0/24,
Trusted (Intranet) 10.10.0.0/24.
The CSO’s home IP is 143.27.43.32, and the RDP server in the DMZ is 161.212.71.14.
Which of the following firewall rules would most effectively prevent the tester from accessing the RDP service while still allowing the CSO’s authorized connection?
