Courseiva
easyMultiple Choice

220-1201 Practice Question: A technician is configuring a new web server that…

A technician is configuring a new web server that must support both standard and encrypted web traffic. Which two ports should be opened in the firewall?

⚠ Common exam trap

CompTIA often tests the distinction between ports used for web services (80/443) versus ports used for remote administration (22, 3389, 5900) or infrastructure services (53, 123), leading candidates to confuse secure web traffic with SSH or RDP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Port 80 and 443

Standard web traffic uses HTTP on port 80, while encrypted web traffic uses HTTPS on port 443. Opening these two ports in the firewall allows the web server to serve both unencrypted and TLS/SSL-encrypted content to clients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port 22 and 21

    Why it's wrong here

    Port 22 carries SSH and port 21 carries FTP control, so neither handles HTTP or HTTPS. Opening these suits remote administration and file transfer, not serving standard and encrypted web traffic on the required ports.

  • ✓

    Port 80 and 443

    Why this is correct

    Port 80 carries unencrypted HTTP, while port 443 carries TLS-encrypted HTTPS, so opening both satisfies the requirement for standard and encrypted web traffic. No other port pair provides this combination; alternatives such as 21/22 or 25/110 serve FTP, SSH, and mail protocols instead.

  • ✗

    Port 3389 and 5900

    Why it's wrong here

    3389 carries RDP and 5900 carries VNC, neither of which serves HTTP or HTTPS traffic. These ports belong on a firewall when remote desktop access to the server is required, not for hosting standard and encrypted web content.

  • ✗

    Port 53 and 123

    Why it's wrong here

    Port 53 carries DNS and port 123 carries NTP, so neither serves HTTP or HTTPS. These belong on a firewall when the server must resolve names or synchronise time, not when hosting standard and encrypted web content.

About these practice questions

Courseiva writes every 220-1201 question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1201

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician is configuring a new web server that must support both standard HTTP and HTTPS traffic. Which two ports should be opened in the firewall?

easy
  • ✓ A.80 and 443
  • B.21 and 22
  • C.8080 and 8443
  • D.25 and 110

Why A: Standard HTTP traffic uses TCP port 80, and HTTPS (HTTP over TLS/SSL) uses TCP port 443. A web server must have both ports open in the firewall to serve unencrypted and encrypted web content respectively, as defined in RFC 7230 and RFC 2818.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.