Courseiva
easyMultiple Choice

ISC2 CC Practice Question: Is configuring a firewall rule to allow inbound…

A network engineer is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which port must be opened?

⚠ Common exam trap

ISC2 often tests the distinction between HTTP (port 80) and HTTPS (port 443), and the trap here is that candidates confuse the two or assume HTTPS uses port 80 because both are web protocols.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

443

HTTPS (HTTP Secure) uses TLS/SSL encryption over TCP port 443 by default. To allow inbound HTTPS traffic to a web server, the firewall rule must permit TCP destination port 443. Port 80 is used for unencrypted HTTP, not HTTPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    3389

    Why it's wrong here

    Port 3389 carries RDP for Windows remote desktop, not HTTPS, so inbound web traffic would be blocked. It is tempting because it is a well-known inbound management port, and would be correct when allowing remote desktop access to a Windows host.

  • ✗

    22

    Why it's wrong here

    Port 22 carries SSH for remote shell access, not HTTPS. It tempts engineers managing Linux web servers, where SSH is the standard administrative channel, but opening it satisfies no browser TLS requirement; HTTPS terminates on 443.

  • ✗

    80

    Why it's wrong here

    Port 80 serves unencrypted HTTP, so browsers reaching it get plaintext, not TLS-protected sessions. It is tempting because port 80 is the traditional web default and often redirects to 443, but the rule must permit 443 itself.

  • ✓

    443

    Why this is correct

    Port 443 carries HTTPS over TLS, satisfying the stem's requirement for inbound secure web traffic. The firewall must permit TCP 443 so clients can establish encrypted sessions with the web server; port 80 would only serve unencrypted HTTP. This directly matches the HTTPS constraint rather than any alternative service.

Go deeper

Related to this question

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.