N10-009 exam dumps

N10-009 practice question 50 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 50

Single answerFTP: 20/21

A network administrator deploys a new firewall in front of an internal FTP server. Remote users report that they can connect to the server and authenticate successfully, but directory listings and file transfers fail. The firewall team confirms that TCP port 21 is allowed inbound to the server. Which additional change is MOST likely needed to restore standard active-mode FTP functionality?

  1. A

    Allow inbound TCP port 20 from the FTP server to the client

  2. B

    Allow inbound TCP port 22 to the FTP server for secure file transfers

  3. C

    Allow inbound UDP port 21 from the client to the FTP server

  4. D

    Allow outbound TCP port 25 from the FTP server to the client

Show answer and explanation

Correct answer: A

Explanation

This scenario reflects a common real-world troubleshooting issue with traditional FTP through firewalls. Standard FTP uses separate channels: TCP 21 for the control session and a separate data channel for listings and file transfers. In active FTP, the server initiates the data connection from TCP port 20 to the client. If only port 21 is permitted, users may be able to log in but data operations will fail. Network+ candidates should recognize that FTP's dual-channel design often requires additional firewall rules or an application-aware firewall/FTP helper. This aligns with standard FTP behavior described in RFC 959 and common firewall best practices for handling legacy FTP traffic.

  • A. Correct.

    Correct. FTP uses TCP port 21 for the control connection and, in active mode, uses TCP port 20 on the server for the data connection. If users can authenticate but cannot list directories or transfer files, the control channel is working but the data channel is being blocked. Allowing the data connection associated with active FTP is the most likely fix.

  • B. Incorrect.

    Incorrect. TCP port 22 is used by SSH and SFTP, which is a different protocol from traditional FTP. Opening port 22 would not restore standard FTP data transfers on an FTP server that is using ports 20 and 21.

  • C. Incorrect.

    Incorrect. FTP uses TCP, not UDP, for both control and data channels. Allowing UDP 21 would not help because the FTP client and server do not use UDP for standard FTP sessions.

  • D. Incorrect.

    Incorrect. TCP port 25 is used for SMTP email transfer, not FTP. This option is a plausible distractor because it is another well-known TCP port, but it has no role in FTP authentication, directory listing, or file transfer operations.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam