Security+

Ports and protocols for Security+

Many scenarios turn on a port number: an exposed database, a cleartext login, the secure replacement for an old protocol. These are the common ones.

Rule of thumbPrefer the encrypted protocol; close every port a system does not need

Common ports

PortProtocolSecure choice
21FTPSFTP over SSH (22) or FTPS
22SSH, SFTP, SCPAlready encrypted
23TelnetSSH (22)
25SMTP relaySMTP with STARTTLS; 587 for submission
53DNSDNSSEC for integrity
80HTTPHTTPS (443)
110 / 143POP3 / IMAPPOP3S (995) / IMAPS (993)
161 / 162SNMPSNMPv3
389LDAPLDAPS (636)
443HTTPSAlready encrypted with TLS
445SMBRestrict to internal networks
3306 / 1433MySQL / Microsoft SQL ServerNever expose to the internet
3389RDPBehind a VPN or jump server

How it shows up on the exam

  • A firewall rule that opens a database port to any source.
  • A protocol that sends passwords in clear text, to be replaced with its encrypted version.
  • Unneeded services left listening, to be disabled when hardening.

Try 3 questions

Question 1Objective 4.1

Which set of actions is an example of hardening a new Linux server?

Question 2Objective 1.3

Company laptops are often left in taxis. Which control best protects the data on a lost laptop's drive?

Question 3Objective 4.1

A company wants every device plugged into an office network port to authenticate before it gets network access. Which standard does this?

Next step

CompTIA's Security+ V8 exam page

Questions people ask

Do I need to memorize every port?

No, but the common ones above come up often in scenarios and labs. Knowing the secure replacement for each is as useful as the number.

Is port 22 secure?

SSH encrypts the session. It should still be limited to the hosts that need it.