Soru

Zorluk: ZorNetworking Ports and Protocols

A security engineer is updating access control lists (ACLs) on an internal firewall to harden domain authentication traffic between web application servers and a central Active Directory server. The organization requires all directory queries to be encrypted in transit while blocking unencrypted directory services. Which of the following port and transport layer protocol combinations must be allowed through the firewall to meet this requirement?

  1. TCP port 636Cevap
  2. B
    TCP port 389
  3. C
    UDP port 53
  4. D
    TCP port 993

Cevap

TCP port 636
Lightweight Directory Access Protocol Secure (LDAPS) encrypts identity and directory service queries using SSL/TLS and listens on TCP port 636 by default. Permitting TCP port 636 ensures directory queries between the web servers and Active Directory remain encrypted.

Adım Adım Çözüm

1
Identify the service and security requirement described in the scenario.
The requirement calls for secure, encrypted directory service queries and Active Directory authentication.
The organization needs to block cleartext authentication and permit encrypted directory access.
2
Determine the default protocol and port for encrypted directory services.
Lightweight Directory Access Protocol Secure (LDAPS) uses TCP port 636.
LDAPS encrypts LDAP communications using TLS/SSL over TCP port 636.
3
Evaluate the non-secure and alternate protocol distractors.
Port 389 is unencrypted LDAP, port 53 is DNS, and port 993 is IMAPS.
Only TCP port 636 specifically satisfies the mandate for secure directory services.

Anahtar Kavram

LDAPS Port and Transport Protocol
Bu soruyu puanla