ISC2 CC Security Operations Practice Question
A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?
⚠ Common exam trap
The trap here is selecting ports for common internet services like DNS or email, but the question specifically asks for HTTP and HTTPS, which are exclusively port 80 and 443.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP 80 and TCP 443
HTTP operates on TCP port 80, and HTTPS operates on TCP port 443. To allow only web traffic, the firewall must permit these ports. Other ports correspond to different services such as FTP, SSH, SMTP, POP3, or DNS, which are not required for web browsing. Therefore, the correct ports are 80 and 443.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP 53 and UDP 53
Why it's wrong here
Port 53 is used for DNS, which resolves domain names to IP addresses. While DNS is essential for web browsing, it is not HTTP or HTTPS traffic. The requirement is to allow only HTTP and HTTPS, so DNS should be handled separately, often via internal resolvers. Opening DNS to the internet directly is not part of this rule.
- ✓
TCP 80 and TCP 443
Why this is correct
HTTP uses TCP port 80, and HTTPS uses TCP port 443. Allowing these ports enables standard web browsing and secure web traffic. This is a common firewall configuration to permit outbound web access while blocking other potentially risky ports. The administrator should also consider application-layer filtering for additional security, but the correct port numbers are 80 and 443.
- ✗
TCP 21 and TCP 22
Why it's wrong here
TCP port 21 is used for FTP, and TCP port 22 is used for SSH. These are not HTTP or HTTPS. Allowing them would permit file transfer and remote shell access, which are not required for web browsing. This would unnecessarily expand the attack surface and does not meet the requirement to allow only HTTP and HTTPS.
- ✗
TCP 25 and TCP 110
Why it's wrong here
TCP port 25 is used for SMTP (email sending), and TCP port 110 is used for POP3 (email retrieval). These are email protocols, not web protocols. Permitting them would allow email traffic, which is not the stated requirement. The administrator should not open these ports for web access.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.