Which ports should I learn first?
Learn the ports for services you can explain: web traffic, name resolution, remote access, email, directories and file sharing. Pair every number with a job and its usual transport. A number without a service name won’t help much when a question asks which firewall rule to change.
The IANA port registry is the reference for assigned service names and numbers. Assigned ports are conventions, not proof of what is running. A service can listen on a different port, and malicious traffic can use a familiar one.
Scroll sideways to see every column.
| Service | Usual port / transport | What to remember |
|---|---|---|
| SSH / SFTP | 22 TCP | Encrypted remote shell; SFTP uses SSH |
| Telnet | 23 TCP | Remote terminal without built-in encryption |
| DNS | 53 UDP and TCP | Name resolution; TCP is also used |
| DHCP for IPv4 | 67 server / 68 client, UDP | Assign network configuration |
| HTTP | 80 TCP | Web traffic without TLS |
| HTTPS | 443 TCP; HTTP/3 uses UDP | HTTP protected with TLS |
| SMTP | 25 TCP | Mail transfer, commonly server to server |
| SMB | 445 TCP | Windows file and printer sharing |
| LDAP | 389 TCP; connectionless LDAP uses UDP | Directory access |
| RDP | 3389 TCP and UDP | Remote desktop |
Which secure alternatives and email ports should I know?
Know how the secure service differs from the older service, especially when a question asks you to protect credentials or data in transit. The secure name isn’t always a simple change of port.
STARTTLS upgrades an existing connection to TLS when correctly required and validated. Implicit TLS starts TLS as soon as the connection opens. This distinction explains why email and directory services can have more than one relevant port.
TLS-protected services make more sense once you separate public-key setup from symmetric traffic protection.
A service may present Base64 values without protecting them; review encoding versus encryption before treating a changed format as confidentiality.
Scroll sideways to see every column.
| Service | Port / transport | Useful distinction |
|---|---|---|
| FTP control / active data | 21 / 20 TCP | Active data uses 20; passive data uses negotiated ports |
| FTPS | 21 TCP explicit TLS / 990 TCP implicit TLS | FTP protected with TLS; different from SFTP |
| TFTP | 69 UDP | Simple file transfer; no built-in encryption |
| SMTP submission | 587 TCP | Message submission, commonly upgraded with STARTTLS |
| SMTP submission with implicit TLS | 465 TCP | TLS begins at connection start |
| POP3 / POP3S | 110 / 995 TCP | Retrieve mail; 995 uses implicit TLS |
| IMAP / IMAPS | 143 / 993 TCP | Mailbox access; 993 uses implicit TLS |
| LDAPS | 636 TCP | LDAP over implicit TLS; LDAP can also use STARTTLS on 389 |
Which monitoring, identity and VPN numbers are worth learning?
Learn the common numbers for network time, monitoring, identity services and VPN setup after you can recall the main service pairs. These help you read rules and identify traffic in practical scenarios.
RADIUS port pairs are a practical reminder that authentication and accounting serve different purposes.
For suspicious traffic, IDS, IPS and SIEM contribute detection, prevention and event correlation rather than simply naming the port.
Scroll sideways to see every column.
| Service | Usual port / transport | Study point |
|---|---|---|
| Kerberos | 88 TCP and UDP | Ticket-based authentication |
| NTP | 123 UDP | Time synchronisation |
| SNMP polling / traps | 161 / 162 UDP | Monitor devices; security depends on version and setup |
| Syslog / syslog over TLS | 514 UDP / 6514 TCP | TLS protects the logging connection |
| RADIUS authentication / accounting | 1812 / 1813 UDP | Separate authentication and accounting services |
| IKE / IPsec NAT traversal | 500 / 4500 UDP | IPsec key negotiation and common NAT traversal |
Does Security+ publish an exact port list I can stop at?
The SY0-701 objectives don’t provide one exhaustive table of port numbers you can safely stop at. Study the network services connected to its security tasks, then use the tables above as a recall aid. Check the exam code on your booking and course materials as versions change.
Avoid spending all your study time memorising unrelated services. Once you recognise a port, explain what a rule would permit, whether the protocol protects traffic, and why a service needs exposure. Those decisions are more useful than recalling a long list in isolation.
An open-port finding from a vulnerability scan needs context before it becomes evidence of an exploitable weakness.
How do I learn ports without mixing them up?
Learn ports in small service groups, then practise recalling the number from the purpose and the purpose from the number. Start with web and remote access, move to mail and directories, then add monitoring and VPNs.
Write a rule in plain language: allow the admin workstation to reach the managed server using SSH. Translate that into a destination, TCP port 22 and a narrow source. Repeat with HTTPS and DNS, including TCP as well as UDP where needed.
A rule allowing destination port 443 doesn’t prove the traffic is harmless. It only permits traffic matching that rule. To see where inspection and segmentation fit, read how network security controls work together.
Remote-access services also face spraying, stuffing and other credential attacks, so memorising their ports is only one part of studying them.
How do I use a port number in a firewall question?
Use the port number as one part of the rule: source, destination, protocol, destination port and action all matter. Consider a user workstation connecting to an HTTPS server. Its source port is usually temporary; the server’s destination port is normally 443.
Opening TCP 443 to every destination is broader than allowing it to one approved server. Direction and scope matter as much as the number. Stateful rules may permit response traffic automatically, so read the policy model in the task.
When a service is business-critical, its recovery-time and data-loss targets help explain why an overbroad rule change can be costly.
Apply the source, destination and service together in a firewall PBQ practice task.