Courseiva
Security Operations →easyMultiple Choice

ISC2 CC Security Operations Practice Question

A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?

⚠ Common exam trap

The trap here is selecting ports for common internet services like DNS or email, but the question specifically asks for HTTP and HTTPS, which are exclusively port 80 and 443.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP 80 and TCP 443

HTTP operates on TCP port 80, and HTTPS operates on TCP port 443. To allow only web traffic, the firewall must permit these ports. Other ports correspond to different services such as FTP, SSH, SMTP, POP3, or DNS, which are not required for web browsing. Therefore, the correct ports are 80 and 443.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP 53 and UDP 53

    Why it's wrong here

    Port 53 is used for DNS, which resolves domain names to IP addresses. While DNS is essential for web browsing, it is not HTTP or HTTPS traffic. The requirement is to allow only HTTP and HTTPS, so DNS should be handled separately, often via internal resolvers. Opening DNS to the internet directly is not part of this rule.

  • ✓

    TCP 80 and TCP 443

    Why this is correct

    HTTP uses TCP port 80, and HTTPS uses TCP port 443. Allowing these ports enables standard web browsing and secure web traffic. This is a common firewall configuration to permit outbound web access while blocking other potentially risky ports. The administrator should also consider application-layer filtering for additional security, but the correct port numbers are 80 and 443.

  • ✗

    TCP 21 and TCP 22

    Why it's wrong here

    TCP port 21 is used for FTP, and TCP port 22 is used for SSH. These are not HTTP or HTTPS. Allowing them would permit file transfer and remote shell access, which are not required for web browsing. This would unnecessarily expand the attack surface and does not meet the requirement to allow only HTTP and HTTPS.

  • ✗

    TCP 25 and TCP 110

    Why it's wrong here

    TCP port 25 is used for SMTP (email sending), and TCP port 110 is used for POP3 (email retrieval). These are email protocols, not web protocols. Permitting them would allow email traffic, which is not the stated requirement. The administrator should not open these ports for web access.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.