Skip to article
Security+ study guide

What ports and protocols do I actually need to memorise for Security+?

For Security+, memorise common service ports together with their purpose and transport: SSH 22, DNS 53, DHCP 67/68, HTTP 80, HTTPS 443, SMTP 25, SMB 445, LDAP 389 and RDP 3389 are a useful starting set. Then learn secure alternatives, monitoring and VPN ports. This is a study shortlist, not a guaranteed exam-only list.

BE The Best Exam Apps team ·
Share

Which ports should I learn first?

Learn the ports for services you can explain: web traffic, name resolution, remote access, email, directories and file sharing. Pair every number with a job and its usual transport. A number without a service name won’t help much when a question asks which firewall rule to change.

The IANA port registry is the reference for assigned service names and numbers. Assigned ports are conventions, not proof of what is running. A service can listen on a different port, and malicious traffic can use a familiar one.

Scroll sideways to see every column.

ServiceUsual port / transportWhat to remember
SSH / SFTP22 TCPEncrypted remote shell; SFTP uses SSH
Telnet23 TCPRemote terminal without built-in encryption
DNS53 UDP and TCPName resolution; TCP is also used
DHCP for IPv467 server / 68 client, UDPAssign network configuration
HTTP80 TCPWeb traffic without TLS
HTTPS443 TCP; HTTP/3 uses UDPHTTP protected with TLS
SMTP25 TCPMail transfer, commonly server to server
SMB445 TCPWindows file and printer sharing
LDAP389 TCP; connectionless LDAP uses UDPDirectory access
RDP3389 TCP and UDPRemote desktop

Which secure alternatives and email ports should I know?

Know how the secure service differs from the older service, especially when a question asks you to protect credentials or data in transit. The secure name isn’t always a simple change of port.

STARTTLS upgrades an existing connection to TLS when correctly required and validated. Implicit TLS starts TLS as soon as the connection opens. This distinction explains why email and directory services can have more than one relevant port.

TLS-protected services make more sense once you separate public-key setup from symmetric traffic protection.

A service may present Base64 values without protecting them; review encoding versus encryption before treating a changed format as confidentiality.

Scroll sideways to see every column.

ServicePort / transportUseful distinction
FTP control / active data21 / 20 TCPActive data uses 20; passive data uses negotiated ports
FTPS21 TCP explicit TLS / 990 TCP implicit TLSFTP protected with TLS; different from SFTP
TFTP69 UDPSimple file transfer; no built-in encryption
SMTP submission587 TCPMessage submission, commonly upgraded with STARTTLS
SMTP submission with implicit TLS465 TCPTLS begins at connection start
POP3 / POP3S110 / 995 TCPRetrieve mail; 995 uses implicit TLS
IMAP / IMAPS143 / 993 TCPMailbox access; 993 uses implicit TLS
LDAPS636 TCPLDAP over implicit TLS; LDAP can also use STARTTLS on 389

Which monitoring, identity and VPN numbers are worth learning?

Learn the common numbers for network time, monitoring, identity services and VPN setup after you can recall the main service pairs. These help you read rules and identify traffic in practical scenarios.

RADIUS port pairs are a practical reminder that authentication and accounting serve different purposes.

For suspicious traffic, IDS, IPS and SIEM contribute detection, prevention and event correlation rather than simply naming the port.

Scroll sideways to see every column.

ServiceUsual port / transportStudy point
Kerberos88 TCP and UDPTicket-based authentication
NTP123 UDPTime synchronisation
SNMP polling / traps161 / 162 UDPMonitor devices; security depends on version and setup
Syslog / syslog over TLS514 UDP / 6514 TCPTLS protects the logging connection
RADIUS authentication / accounting1812 / 1813 UDPSeparate authentication and accounting services
IKE / IPsec NAT traversal500 / 4500 UDPIPsec key negotiation and common NAT traversal

Does Security+ publish an exact port list I can stop at?

The SY0-701 objectives don’t provide one exhaustive table of port numbers you can safely stop at. Study the network services connected to its security tasks, then use the tables above as a recall aid. Check the exam code on your booking and course materials as versions change.

Avoid spending all your study time memorising unrelated services. Once you recognise a port, explain what a rule would permit, whether the protocol protects traffic, and why a service needs exposure. Those decisions are more useful than recalling a long list in isolation.

An open-port finding from a vulnerability scan needs context before it becomes evidence of an exploitable weakness.

How do I learn ports without mixing them up?

Learn ports in small service groups, then practise recalling the number from the purpose and the purpose from the number. Start with web and remote access, move to mail and directories, then add monitoring and VPNs.

Write a rule in plain language: allow the admin workstation to reach the managed server using SSH. Translate that into a destination, TCP port 22 and a narrow source. Repeat with HTTPS and DNS, including TCP as well as UDP where needed.

A rule allowing destination port 443 doesn’t prove the traffic is harmless. It only permits traffic matching that rule. To see where inspection and segmentation fit, read how network security controls work together.

Remote-access services also face spraying, stuffing and other credential attacks, so memorising their ports is only one part of studying them.

How do I use a port number in a firewall question?

Use the port number as one part of the rule: source, destination, protocol, destination port and action all matter. Consider a user workstation connecting to an HTTPS server. Its source port is usually temporary; the server’s destination port is normally 443.

Opening TCP 443 to every destination is broader than allowing it to one approved server. Direction and scope matter as much as the number. Stateful rules may permit response traffic automatically, so read the policy model in the task.

When a service is business-critical, its recovery-time and data-loss targets help explain why an overbroad rule change can be costly.

Apply the source, destination and service together in a firewall PBQ practice task.

Best Exam Apps

Prepare with CompTIA Security+ Practice

Concept lessons, explained practice, a firewall exercise and a daily study route across the five SY0-701 domains.

See the app
Download on the App StoreGet it on Google Play