N10-009 exam dumps

N10-009 practice question 72 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 72

Single answerHTTPS: 443

A company hosts a customer portal on a web server in its DMZ. Users report they can browse the portal internally, but external customers cannot access it using the secure URL https://portal.company.com. A network technician confirms the server is online, DNS resolves correctly to the public IP address, and the edge firewall currently allows inbound TCP 80 to the web server. Which action should the technician take FIRST to restore secure access for external users?

  1. A

    Allow inbound TCP 443 from the internet to the web server

  2. B

    Allow inbound UDP 443 from the internet to the web server

  3. C

    Allow inbound TCP 22 from the internet to the web server

  4. D

    Change the DNS record for portal.company.com to use port 80

Show answer and explanation

Correct answer: A

Explanation

The key issue is that the portal must be reachable over HTTPS, which by standard convention uses TCP port 443. Since the firewall only allows inbound TCP 80, external users can potentially reach HTTP but not HTTPS. The best first action is to permit or forward TCP 443 to the web server. This aligns with common firewall and web publishing practices and with IANA standard service port assignments, where HTTPS is associated with TCP 443. DNS resolution being correct rules out a name-resolution issue, and the server being online rules out a host outage. The scenario tests practical troubleshooting: identify the service, verify the protocol and port required, and correct the firewall rule blocking secure access.

  • A. Correct.

    Correct. HTTPS uses TCP port 443 for encrypted web traffic. If users are trying to reach the site with an https:// URL and the firewall only permits TCP 80, external secure connections will fail even if DNS and the server itself are functioning properly. Opening or forwarding inbound TCP 443 to the web server is the appropriate first step.

  • B. Incorrect.

    Incorrect. Standard HTTPS does not use UDP 443 in the typical web-server scenario tested on Network+. While some newer web technologies such as HTTP/3 can use UDP 443, the classic and expected Network+ association for HTTPS is TCP 443. Choosing this option reflects confusion between transport protocols.

  • C. Incorrect.

    Incorrect. TCP 22 is used for SSH remote administration, not for end-user secure web access. Opening SSH would not allow customers to browse the portal and could create unnecessary security exposure if enabled from the internet without a business need.

  • D. Incorrect.

    Incorrect. DNS records map names to IP addresses, not to TCP or UDP ports. Users specify the port through the protocol or URL, and HTTPS defaults to port 443. Changing DNS would not redirect HTTPS traffic to port 80.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam