ISC2 Certified in Cybersecurity (CC)Network SecurityEasy
A system administrator is configuring a new web server that will host a public-facing e-commerce application. To ensure that only legitimate web traffic (HTTP/HTTPS) can reach the server and to prevent other types of network attacks, which network protocol ports should be explicitly opened on the firewall for this server?
- APort 25 (SMTP) and Port 110 (POP3)
- BPort 21 (FTP) and Port 23 (Telnet)
- CPort 22 (SSH) and Port 3389 (RDP)
- DPort 80 (HTTP) and Port 443 (HTTPS)
Show answer & explanationAnswer & explanation
Correct answer: D. Port 80 (HTTP) and Port 443 (HTTPS)
HTTP (Port 80) and HTTPS (Port 443) are the standard ports for web traffic, which is essential for a public-facing e-commerce application.
Why the other options are wrong
- A. SMTP and POP3 are for email services, which are unrelated to hosting a public web application.
- B. FTP and Telnet are for file transfer and remote access, respectively, and are not typically needed for a public web server, especially Telnet due to its insecurity.
- C. SSH and RDP are for secure remote administration; while SSH might be used for server management, it's not for public web traffic, and RDP is not common for Linux web servers.
Common Network Ports
Standardized port numbers used by various network protocols to identify specific services running on a server.
- Port 80: HTTP (Hypertext Transfer Protocol) for unencrypted web traffic.
- Port 443: HTTPS (Hypertext Transfer Protocol Secure) for encrypted web traffic.
- Firewalls use port numbers to filter traffic and enhance security.
Memory trick: 80 Web Wonders, 443 Safe Sites, 21 Files Fly, 22 SSH Secrets.