N10-009 exam dumps

N10-009 practice question 81 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 81

Single answerLDAPS: 636

A systems administrator is configuring a new identity-aware application to authenticate users against the company's Active Directory over an encrypted connection. The application is set to use the domain controllers' hostnames, and the firewall team confirms that only one additional outbound port can be opened from the application server to the domain controllers. Which port should the administrator request to allow secure LDAP communication without using StartTLS?

  1. A

    389

  2. B

    443

  3. C

    636

  4. D

    3268

Show answer and explanation

Correct answer: C

Explanation

The correct answer is 636 because LDAPS uses TCP port 636 for encrypted LDAP sessions. In real-world deployments, applications that must bind securely to Active Directory often require both connectivity to the domain controller and a trusted server certificate on the domain controller that matches the hostname used by the client. This is especially important since the scenario states that the application uses the domain controllers' hostnames. Port 389 is for LDAP and may support StartTLS, but the question explicitly excludes StartTLS. Port 3268 is for Global Catalog queries and is not encrypted by default; secure Global Catalog traffic uses 3269. Microsoft Active Directory documentation and standard LDAP service port assignments support these port mappings and best practices.

  • A. Incorrect.

    Port 389 is the default port for standard LDAP. Although LDAP on 389 can be upgraded to encryption with StartTLS in some environments, the question specifically asks for secure LDAP communication without using StartTLS. Therefore, 389 is not the best answer in this scenario.

  • B. Incorrect.

    Port 443 is used for HTTPS web traffic, not LDAP directory queries. A candidate might choose this because it is a common secure port, but LDAPS does not run on 443.

  • C. Correct.

    Port 636 is correct. LDAPS uses TCP port 636 for LDAP over SSL/TLS, providing encrypted directory communication from the start of the session rather than negotiating encryption later with StartTLS.

  • D. Incorrect.

    Port 3268 is the default Global Catalog port for LDAP in Active Directory, but it is not encrypted by default. A related secure Global Catalog port is 3269, but that is not listed here. Choosing 3268 reflects confusion between directory search scope and transport security.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam