Yes, you are right. Its fairly easy.
Open the xml file /app/etc/local.xml, and find the <frontName> tag, and then change the ‘admin’ part it to something secure
<frontName><![CDATA[new-secret-admin-path]]></frontName>