N10-009 exam dumps

N10-009 practice question 71 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 71

Single answerLDAP: 389

A network administrator is troubleshooting a new internal web application that authenticates users against the company directory. Users report that they can log in from workstations on the LAN, but authentication fails from a server in a different VLAN after a new firewall rule set was applied. The application documentation states it uses standard LDAP to query the directory service. Which firewall change is most likely needed to restore authentication while following the documented protocol requirement?

  1. A

    Allow TCP port 389 from the application server VLAN to the directory server

  2. B

    Allow UDP port 389 from the application server VLAN to the directory server

  3. C

    Allow TCP port 636 from the application server VLAN to the directory server

  4. D

    Allow TCP port 88 from the application server VLAN to the directory server

Show answer and explanation

Correct answer: A

Explanation

LDAP commonly listens on TCP port 389 for standard directory access. In real environments, directory-integrated applications often fail after segmentation or firewall changes because required ports between the application tier and directory servers are blocked. If the application is documented to use LDAP, the most direct and accurate fix is to permit TCP 389. By contrast, TCP 636 is for LDAPS, which is a different configuration choice and typically requires the application to be explicitly set up for secure LDAP with appropriate certificates. Port 88 is for Kerberos and would not satisfy a standard LDAP directory query requirement. This aligns with common vendor documentation and operational best practices for directory service connectivity, including Microsoft Active Directory and OpenLDAP deployments, where LDAP uses 389/TCP and LDAPS uses 636/TCP.

  • A. Correct.

    Correct. Standard LDAP uses TCP port 389 for directory queries and authentication-related lookups when the application is configured for LDAP rather than LDAPS. If the application documentation specifically says it uses standard LDAP, the firewall must permit TCP 389 between the application server and the directory server.

  • B. Incorrect.

    Incorrect. While some directory-related services can use UDP in certain contexts, standard LDAP communication for client queries is typically over TCP 389. Choosing UDP 389 reflects a common misunderstanding that directory traffic behaves like lightweight name-resolution protocols.

  • C. Incorrect.

    Incorrect. TCP 636 is used for LDAPS, which is LDAP over SSL/TLS. This would be appropriate only if the application were specifically configured to use LDAPS or secure LDAP. The scenario says the application documentation specifies standard LDAP, so opening 636 alone would not match the stated requirement.

  • D. Incorrect.

    Incorrect. TCP/UDP port 88 is associated with Kerberos authentication, not standard LDAP queries. Someone might choose this because Active Directory environments often use Kerberos for authentication, but the scenario explicitly says the application uses LDAP to query the directory service.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam