Soru

Zorluk: OrtaCommon Ports and Protocols

A network administrator is creating an Access Control List (ACL) on an enterprise router to allow branch office workstations to obtain initial authentication tickets from an internal Active Directory Domain Controller. Which of the following port and transport protocol combinations must be permitted through the firewall to enable this Kerberos ticket-granting service?

  1. TCP and UDP port 88Cevap
  2. B
    TCP port 389
  3. C
    UDP port 445
  4. D
    TCP port 636

Cevap

TCP and UDP port 88 is the correct combination required for Kerberos authentication services.
Kerberos is the primary authentication mechanism for Active Directory domains. It operates over TCP and UDP port 88 to communicate with the Key Distribution Center (KDC) to request and issue authentication tickets.

Adım Adım Çözüm

1
Identify the protocol required for ticket-granting domain authentication.
Active Directory domain ticket-granting services rely on the Kerberos authentication protocol.
Kerberos handles user identification and initial ticket issuing within Active Directory.
2
Determine the standard port and transport protocol binding for Kerberos.
Kerberos uses port 88 over both UDP (for typical ticket requests) and TCP (for larger payload responses).
Firewalls must allow port 88 for both TCP and UDP traffic to maintain proper authentication functionality.

Anahtar Kavram

Standard Well-Known Ports and Authentication Protocols
Bu soruyu puanla