N10-009 exam dumps

N10-009 practice question 79 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 79

Single answerSMTPS: 587

A company has migrated users to a new cloud email provider. After the change, users can receive email but cannot send email from their mail clients when working remotely. The help desk confirms the clients are configured to use the provider's SMTP submission service on port 587 with authentication. A network administrator captures traffic and sees the TCP three-way handshake complete to the mail server, but the session fails immediately after the client attempts to begin encrypted communication. Which of the following is the MOST likely cause?

  1. A

    A firewall or security device is interfering with STARTTLS on SMTP submission over port 587

  2. B

    The client should be using POP3 over port 110 instead of SMTP over port 587 for sending mail

  3. C

    The mail server should be configured to accept SMTPS only on port 995

  4. D

    DNS is failing because SMTP requires an SRV record instead of an A or MX record

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical knowledge of SMTP submission on port 587. In modern email deployments, port 587 is the standard port for authenticated client message submission, commonly using STARTTLS to encrypt the session after the initial SMTP negotiation. If the TCP handshake completes but the connection fails when encrypted communication begins, the problem is often related to TLS negotiation being blocked or altered by a firewall, proxy, IDS/IPS, or content inspection device. By contrast, POP3 ports 110 and 995 are for message retrieval, not sending. DNS problems can affect connectivity, but they do not specifically explain a failure that occurs only after the client starts TLS. This aligns with common best practices reflected in email submission standards and provider documentation, where port 587 with SMTP AUTH and STARTTLS is the recommended configuration for outbound client email.

  • A. Correct.

    Correct. Port 587 is the standard message submission port used by mail clients to send outbound email, typically with SMTP authentication and STARTTLS to upgrade the connection to TLS. If the TCP connection succeeds but the session fails when encryption begins, a firewall, proxy, or security appliance that blocks or improperly inspects STARTTLS negotiation is a likely cause.

  • B. Incorrect.

    Incorrect. POP3 on port 110 is used for retrieving email from a mailbox, not sending email. A user who can receive but not send mail would still need SMTP submission for outbound mail. This option reflects a common confusion between retrieval protocols and sending protocols.

  • C. Incorrect.

    Incorrect. Port 995 is associated with POP3 over TLS/SSL, not SMTP submission. While SMTP has historically been associated with implicit TLS on port 465 in some deployments, port 995 is not used for SMTP. This distractor targets confusion between secure mail-related ports.

  • D. Incorrect.

    Incorrect. SMTP client submission to a known hostname commonly relies on standard DNS resolution such as A or AAAA records for that host. MX records are used for mail exchanger routing between mail servers, not typically for end-user client submission settings, and SMTP does not require an SRV record in this scenario. DNS issues would more likely prevent initial connection rather than specifically breaking the session at the start of encryption.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam