N10-009 exam dumps

N10-009 practice question 49 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 49

Single answerPorts & Protocols:

A company migrates its email security gateway to a new cloud service. After the cutover, internal users can send email to external recipients, but external partners report that messages to the company's domain are failing. The network administrator confirms the public MX record points to the new gateway and that outbound web access works from the gateway management interface. A perimeter firewall sits between the internet and the new service connector on-premises. Which firewall rule should the administrator verify first to restore inbound email delivery?

  1. A

    Allow TCP 25 from the internet to the mail gateway

  2. B

    Allow TCP 110 from the internet to the mail gateway

  3. C

    Allow TCP 143 from the internet to the mail gateway

  4. D

    Allow UDP 53 from the internet to the mail gateway

Show answer and explanation

Correct answer: A

Explanation

The best answer is to verify TCP port 25 inbound to the mail gateway. In normal email flow, external mail servers perform DNS MX lookups for the recipient domain and then establish an SMTP session to the destination over TCP 25. POP3 (TCP 110) and IMAP (TCP 143) are mailbox access protocols used by end users, not by remote servers delivering mail. DNS on UDP/TCP 53 supports name resolution, but with the MX record already confirmed, the most immediate firewall dependency for inbound delivery is SMTP on TCP 25. This aligns with standard mail transport behavior documented in SMTP standards such as RFC 5321 and common enterprise firewall best practices for permitting only required service ports.

  • A. Correct.

    Correct. SMTP uses TCP port 25 for server-to-server mail transfer. Inbound email from external mail systems to the organization's mail gateway depends on TCP 25 being reachable. If the MX record already points to the new gateway, blocking or missing access on TCP 25 is the most likely cause of failed inbound delivery.

  • B. Incorrect.

    Incorrect. TCP 110 is POP3, which is used by clients to retrieve email from a mailbox server. It is not the port used by external mail servers to deliver inbound mail to the organization's domain. Someone might choose this if they confuse user email access protocols with mail transport protocols.

  • C. Incorrect.

    Incorrect. TCP 143 is IMAP, another client retrieval protocol for accessing stored mailbox content. Like POP3, it is not used for SMTP mail delivery between organizations. This distractor targets the common misconception that any email-related port could affect inbound message receipt.

  • D. Incorrect.

    Incorrect. UDP 53 is DNS query traffic. DNS is relevant to mail flow because senders use MX lookups to find the destination server, but the scenario already states the public MX record points to the new gateway. If DNS resolution were the issue, the symptom would be name resolution problems rather than a specific failure to accept inbound SMTP connections at the gateway.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam