ISC2 CC Network Security Practice Question
Which common port is used by DNS and which transport layer protocol does it primarily use?
⚠ Common exam trap
The trap is the assumption that DNS is 'UDP only' because most queries use UDP; the exam tests whether you know TCP/53 is also required for zone transfers and large responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port 53, both UDP and TCP
DNS uses port 53 for both UDP and TCP: UDP is used for standard queries and responses because it is fast and low-overhead, while TCP is used for zone transfers, DNSSEC responses, and queries with responses larger than 512 bytes (or EDNS0-negotiated sizes). This dual-protocol design is why the correct answer must include both.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port 53, UDP only
Why it's wrong here
DNS uses port 53 over both UDP and TCP, not UDP alone; TCP is required for zone transfers and responses exceeding 512 bytes. The port is correct, which tempts, but claiming UDP only ignores the transport DNS switches to when truncation occurs.
- ✗
Port 161, UDP
Why it's wrong here
Port 161 carries SNMP, not DNS, and is used for network device polling. It is tempting because SNMP also runs over UDP, matching the transport half of the question, but the port number itself is wrong for name resolution queries.
- ✓
Port 53, both UDP and TCP
Why this is correct
DNS queries and responses travel over port 53. UDP carries ordinary lookups for speed, while TCP handles zone transfers and responses exceeding 512 bytes, or when truncation occurs. The protocol choice therefore depends on the query type, not a single transport.
- ✗
Port 53, TCP only
Why it's wrong here
DNS uses port 53 over both UDP and TCP, not TCP alone; UDP handles standard queries while TCP covers zone transfers and large responses. The port is right, which is tempting, but restricting the transport to TCP only misstates how DNS primarily operates.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
Key term
Domain Name System Security Extensions
A set of protocols that add digital signatures to DNS data to verify its authenticity and integrity.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.