CompTIA DataSys+ (DS0-001)Database DeploymentMedium

A database administrator is planning the network configuration for a new database server. The database will handle sensitive customer data and connect to an application server. To ensure secure communication between the application and the database, which port configuration is generally considered a best practice for MySQL?

  1. AOpen port 22 (SSH) for all incoming connections.
  2. BRestrict inbound traffic to port 3306 (MySQL default) from only the application server's IP address.
  3. CChange the default MySQL port to a random high-numbered port (e.g., 50000) and open it to the internet.
  4. DAllow all incoming connections to port 3306 for ease of access.
Show answer & explanation

Correct answer: B. Restrict inbound traffic to port 3306 (MySQL default) from only the application server's IP address.

Restricting inbound traffic to the database port (3306 for MySQL) to only the IP addresses of authorized application servers is a fundamental security best practice. This implements the principle of least privilege for network access, minimizing the attack surface.

Why the other options are wrong

  • A. Port 22 (SSH) is for secure shell access, not database communication, and should be restricted, not opened to all.
  • C. Changing the default port (security by obscurity) and then opening it to the internet provides no real security benefit and still exposes the database to potential attacks.
  • D. Allowing all incoming connections to the database port is a major security vulnerability and should never be done for production systems.

Database Network Security

Database network security involves controlling access to database ports and encrypting communication channels to protect data in transit and prevent unauthorized access.

  • Implement firewalls to restrict inbound/outbound traffic.
  • Use the principle of least privilege for network access (only allow necessary IPs).
  • Encrypt data in transit using SSL/TLS.
  • Avoid exposing database ports directly to the internet.

Memory trick: Restrict 'R'eally 'R'equired 'R'outes.

More Database Deployment questions