DEV Community

Moznu
Moznu

Posted on Originally published at quizcram.com

CompTIA A+ Port Numbers: The Complete Quick-Reference Cheat Sheet (Core 1 220-1101)

Every candidate sitting for the CompTIA A+ Core 1 (220-1101) exam encounters port questions—either directly ("Which port does LDAPS operate on?") or embedded inside performance-based firewall troubleshooting questions.

Knowing your ports by heart is free points on test day. Here is the authoritative breakdown of every required port, categorized by service type, along with memory hooks to lock them in.


1. Quick-Reference Master Table

Port Protocol / Service Transport Description Secure Alternative
20/21 FTP (File Transfer Protocol) TCP Unencrypted file transfer (20: Data, 21: Control) SFTP (Port 22) / FTPS (Port 990/989)
22 SSH (Secure Shell) / SFTP TCP Encrypted terminal access & secure file transfer N/A (Standard secure protocol)
23 Telnet TCP Unencrypted remote command-line terminal SSH (Port 22)
25 SMTP (Simple Mail Transfer) TCP Sending outbound mail between mail servers SMTPS (Port 465 or 587)
53 DNS (Domain Name System) UDP/TCP Resolves FQDN hostnames to IP addresses DNS over HTTPS (Port 443)
67/68 DHCP (Dynamic Host Config) UDP Assigns dynamic IP configurations (67: Server, 68: Client) N/A
69 TFTP (Trivial FTP) UDP Lightweight, connectionless file transfer (PXE booting) SFTP / SCP
80 HTTP (HyperText Transfer) TCP Unencrypted web traffic HTTPS (Port 443)
110 POP3 (Post Office Protocol 3) TCP Downloads mail to a local client and deletes from server POP3S (Port 995)
123 NTP (Network Time Protocol) UDP Synchronizes clock time across network hosts N/A
137-139 NetBIOS UDP/TCP Legacy Windows LAN name resolution & file sharing Direct SMB (Port 445)
143 IMAP (Internet Message Access) TCP Synchronizes mail folders across multiple clients IMAPS (Port 993)
161/162 SNMP (Simple Network Mgmt) UDP Network monitoring & device traps (161: Queries, 162: Traps) SNMPv3 (encrypted)
389 LDAP (Lightweight Directory Access) TCP/UDP Queries Active Directory / directory services LDAPS (Port 636)
443 HTTPS (HTTP Secure) TCP TLS/SSL encrypted web traffic N/A (Gold standard)
445 SMB (Server Message Block) TCP Modern Windows network file & print sharing N/A
636 LDAPS (LDAP Secure) TCP TLS-encrypted Active Directory queries N/A
3389 RDP (Remote Desktop Protocol) TCP/UDP Microsoft graphical remote desktop session N/A

2. Web & Mail Protocols: The Insecure vs. Secure Pairs

CompTIA loves asking which secure protocol replaces an obsolete legacy protocol in a hardened environment:

Web Traffic

  • HTTP (80) ➔ Replaced by HTTPS (443). Uses TLS to encrypt session data.

Email Protocols

  • Outbound Sending:
    • Unencrypted: SMTP (Port 25)
    • Secure Submission: Port 587 (STARTTLS) or Port 465 (SMTPS).
  • Inbound Retrieval:
    • POP3: Insecure on Port 110, Secure on Port 995. Downloads and stores locally.
    • IMAP: Insecure on Port 143, Secure on Port 993. Keeps mail on the server and synchronizes across phone/laptop.

3. Remote Management: Telnet vs. SSH vs. RDP

  • Telnet (Port 23): Transmits commands and passwords in plaintext. Never use over an untrusted network.
  • SSH (Port 22): Uses public-key cryptography to provide an encrypted CLI session. Also powers SFTP.
  • RDP (Port 3389): Microsoft's graphical remote desktop connection tool.

4. 4 Memory Hooks for Exam Day

  1. "DNS = Half a Dollar + 3": DNS is Port 53. (Also remember it uses UDP for standard queries and TCP for large zone transfers).
  2. "SSH is 22, Telnet is 23": Telnet is one step after SSH, but SSH is encrypted while Telnet is exposed.
  3. "RDP has 4 digits: 3-3-8-9": Remind yourself of the 3389 cadence—3, 3, then (8, 9).
  4. "POP3S (995) & IMAPS (993)": Notice how both secure mail retrieval ports are in the 990s.

5. Sample CompTIA Practice Questions

Question 1:

A network administrator needs to securely query an Active Directory server across an external branch link. Which port must be opened on the edge firewall?

A. 389

B. 445

C. 636

D. 3389

Correct Answer: C (Port 636 - LDAPS)

Explanation: Standard LDAP operates on port 389 in cleartext. Over an untrusted link, secure LDAP over TLS (LDAPS) running on port 636 is strictly required.

Question 2:

A technician setting up a local mail server notices outgoing client mail is blocked by the upstream ISP on port 25. Which alternative port should the clients configure for authenticated submission?

A. 110

B. 143

C. 443

D. 587

Correct Answer: D (Port 587)

Explanation: ISPs frequently block port 25 to prevent spam bots. Modern email clients submit outbound messages via SMTP submission on port 587 using TLS.


Test Your Full Exam Readiness

Are you scoring consistently above the 75% pass mark on CompTIA A+ Core 1 questions?

You can test yourself with realistic, timed practice tests, complete with sourced explanations for every single objective on QuizCram's free CompTIA A+ practice test.

Top comments (0)