Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityEasy
A network security administrator is configuring a new firewall and wants to allow HTTP and HTTPS traffic to a web server in the DMZ, while blocking all other incoming traffic to that server. Which of the following ports must be explicitly allowed for this configuration?
- A22 and 23
- B25 and 110
- C20 and 21
- D80 and 443
Show answer & explanationAnswer & explanation
Correct answer: D. 80 and 443
HTTP traffic uses port 80 and HTTPS traffic uses port 443. To allow these services, the firewall must explicitly permit traffic on these standard ports.
Why the other options are wrong
- A. Ports 22 and 23 are used for SSH (Secure Shell) and Telnet, respectively, not HTTP/HTTPS.
- B. Ports 25 and 110 are used for SMTP (Simple Mail Transfer Protocol) and POP3 (Post Office Protocol version 3), respectively, for email services.
- C. Ports 20 and 21 are used for FTP (File Transfer Protocol), not HTTP/HTTPS.
Common Network Ports
Specific numerical labels used to identify different services or applications running on a network device, enabling communication between them.
- Ports 0-1023 are well-known ports, assigned to common services.
- Ports 1024-49151 are registered ports, often used by specific applications.
- Ports 49152-65535 are dynamic/private ports, used for client-side connections.
Memory trick: Each application has its own door number to connect.