Courseiva
mediumMultiple Choice

220-1201 Practice Question: A technician is setting up a new web server that…

A technician is setting up a new web server that must be accessible from the internet using HTTPS. The server is behind a firewall that performs port forwarding. After configuration, external users cannot reach the server, but internal users can. Which protocol and port combination must be forwarded to the server?

⚠ Common exam trap

Candidates often mistakenly choose UDP 443 due to confusion with QUIC or DNS, but the CompTIA A+ exam expects TCP 443 as the standard for HTTPS traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP 443

HTTPS uses TCP port 443 by default. Since the server must be accessible from the internet via HTTPS, the firewall must forward TCP port 443 to the server's internal IP address. Internal users can reach the server because they are on the same local network and bypass the firewall's port forwarding rule, but external traffic on port 443 is blocked unless the rule is correctly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP 80

    Why it's wrong here

    TCP 80 serves plain HTTP, not HTTPS, so external clients requesting TLS on 443 are never forwarded. It is tempting because port 80 is the standard web port, and would be correct if the site were published over unencrypted HTTP instead of requiring HTTPS.

  • ✗

    UDP 443

    Why it's wrong here

    HTTPS uses TCP, not UDP; UDP 443 carries protocols such as QUIC, so the firewall forwards no TCP session and browsers still fail. It is tempting because the port number matches HTTPS, and would be correct for UDP-based QUIC traffic rather than a standard TLS web server.

  • ✓

    TCP 443

    Why this is correct

    HTTPS uses TCP 443, so the firewall must forward inbound TCP 443 to the web server's internal address. Internal users succeed because they reach the server directly, bypassing the firewall's port-forwarding rule, which explains why only external access fails.

  • ✗

    TCP 3389

    Why it's wrong here

    TCP 3389 carries RDP for remote desktop, not HTTPS, so forwarding it leaves web traffic blocked. It is tempting because 3389 is a well-known port used for remote server administration, and would be correct if the requirement were to reach the server's desktop remotely rather than serve HTTPS.

About these practice questions

Courseiva writes every 220-1201 question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.