Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A security auditor is reviewing a company's network configuration and identifies several servers that are directly accessible from the internet, but only need to serve web traffic (HTTP/HTTPS). To minimize the attack surface, the auditor recommends restricting inbound traffic to only the necessary ports. Which port numbers should be explicitly allowed for HTTP and HTTPS traffic?

  1. A21 and 23
  2. B80 and 443
  3. C22 and 3389
  4. D25 and 110
Show answer & explanation

Correct answer: B. 80 and 443

HTTP (Hypertext Transfer Protocol) traffic typically uses port 80, and HTTPS (Hypertext Transfer Protocol Secure) traffic uses port 443. These are the standard ports for web servers, and allowing only these ports minimizes the attack surface by blocking all other unnecessary inbound connections.

Why the other options are wrong

  • A. Port 21 is for FTP (File Transfer Protocol) and Port 23 is for Telnet, neither of which is for web traffic.
  • C. Port 22 is for SSH (Secure Shell) and Port 3389 is for RDP (Remote Desktop Protocol), neither is for web traffic.
  • D. Port 25 is for SMTP (Simple Mail Transfer Protocol) and Port 110 is for POP3 (Post Office Protocol version 3), both are for email, not web traffic.

Common Network Ports

Standardized communication endpoints used by network protocols for specific services.

  • Ports 0-1023 are 'well-known ports' assigned to common services.
  • Blocking unnecessary ports reduces the attack surface.
  • HTTP uses 80, HTTPS uses 443.

Memory trick: Web traffic is Hella Hot on 80 and 443.

More Network Security questions