Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

Which of the following ports is used by HTTPS?

⚠ Common exam trap

Many candidates confuse port 80 (HTTP) with port 443 (HTTPS); candidates who memorize only 'web = 80' pick A without noticing the 'S' in HTTPS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

443

HTTPS (Hypertext Transfer Protocol Secure) operates over TCP port 443 by default, using TLS to encrypt HTTP traffic between client and server. This is the IANA-assigned well-known port for HTTPS, so any browser request to https:// implicitly targets port 443 unless overridden. Port 80 is the counterpart for unencrypted HTTP, which is why the two are so often confused.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    80

    Why it's wrong here

    Port 80 carries unencrypted HTTP; HTTPS uses 443 with TLS. Port 80 is the right answer when a question asks about plain web traffic or a URL beginning http://, but it provides no transport encryption for the session.

  • ✗

    21

    Why it's wrong here

    Port 21 carries FTP control commands, not HTTPS traffic, so it cannot satisfy a requirement for encrypted web access on the standard TLS port. It is tempting because 21 is a well-known, memorised port number, and it would be the correct choice if the question instead asked which port FTP uses for its control connection.

  • ✗

    25

    Why it's wrong here

    Port 25 carries SMTP for mail relay, so it cannot serve HTTPS traffic. It is tempting because 25 is a well-known assigned port, but that assignment belongs to email transport; HTTPS listens on TCP 443, which the scenario requires.

  • ✓

    443

    Why this is correct

    HTTPS uses TCP port 443 by default, carrying HTTP traffic encrypted with TLS. Port 80 serves plain HTTP, while 22 and 3389 handle SSH and RDP respectively. Browsers and servers therefore negotiate secure web sessions on 443 unless an administrator configures a non-standard port.

Go deeper

Related to this question

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.