N10-009 exam dumps

N10-009 practice question 48 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 48

Single answerPorts & Protocols:

A systems administrator has moved a branch office file transfer process from legacy FTP to a more secure solution. After the change, users report that they can connect to the remote Linux server and transfer files successfully using an SSH-based client, but a firewall review shows that outbound TCP 21 is still allowed while the security team wants to restrict traffic to only the minimum required port. Which port should the administrator allow for this file transfer solution to continue working?

  1. A

    TCP 20

  2. B

    TCP 21

  3. C

    TCP 22

  4. D

    TCP 990

Show answer and explanation

Correct answer: C

Explanation

This scenario tests the ability to distinguish among secure file transfer protocols and their associated ports in a real firewall configuration task. SFTP is not FTP with encryption; it is a separate protocol that operates over SSH, typically on TCP 22. Standard FTP uses TCP 21 for the control channel and TCP 20 for data in active mode, while FTPS commonly uses TCP 21 for explicit TLS or TCP 990 for implicit TLS. In practice, Network+ candidates should know that reducing firewall rules to the minimum required access is a security best practice aligned with least privilege. Vendor and standards documentation consistently identifies SSH on TCP 22 and SFTP as an SSH subsystem rather than an FTP variant.

  • A. Incorrect.

    TCP 20 is traditionally associated with FTP data traffic in active mode, not with SSH-based file transfer. Someone might choose this if they remember FTP uses ports 20 and 21, but SFTP does not rely on the separate FTP control/data channel model.

  • B. Incorrect.

    TCP 21 is the standard FTP control port. It is not the correct choice for an SSH-based file transfer client. This is a common misconception when administrators equate all file transfer services with FTP-related ports.

  • C. Correct.

    TCP 22 is correct because SFTP, or SSH File Transfer Protocol, runs over SSH and uses TCP port 22 by default. If users are connecting with an SSH-based client and successfully transferring files to a Linux server, the firewall should permit TCP 22 rather than FTP ports.

  • D. Incorrect.

    TCP 990 is used by implicit FTPS, which is FTP secured with TLS/SSL in a specific deployment mode. It is not used for SFTP. This distractor is plausible because both FTPS and SFTP are secure file transfer methods, but they are different protocols with different ports.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam