Ports and services interview questions, answered properly.
Most candidates can name a port. Far fewer can say what it means in a log, why the transport matters, or what to do when they see an unexpected one. That gap is exactly where interviews are lost — and it is fixable.
Naming the port is not the answer
Ask a candidate what port LDAP uses and you will usually get 389. That is correct, and it is also where the answer ends. Ask what that tells them about the traffic in front of them, why it is on that port rather than another, or what they would do about a host suddenly talking LDAP to an unfamiliar server, and the room goes quiet.
Interviewers are not testing memory. They are testing whether you understand what you are looking at. A port is a fact; what matters is the reasoning around it — the direction of the traffic, the transport protocol, whether the port matches the behaviour, and whether it appears where it should not.
This page gives you both halves. First the reference list, with the transport protocol on every row, so you are never giving half an answer again. Then the part that actually separates candidates: how to reason about a port you have never seen, how to read one in a log or a firewall line, and 38 questions of the kind you will be asked, with answers written the way an interviewer wants to hear them.
The ports that actually get asked
Learn the number, the transport, and one sentence about what it carries. That third column is what turns a memorised list into an answer.
| Port | Service | Transport | Why it matters |
|---|---|---|---|
| 20, 21 | FTP — data (20), control (21) | TCP | 21 carries the login and commands, 20 the data in active mode. Passive mode negotiates a random high data port instead. Credentials and files travel in cleartext. |
| 22 | SSH | TCP | Encrypted remote shell, file transfer (SCP/SFTP) and tunnelling. Brute force and tunnelled traffic both hide here. |
| 23 | Telnet | TCP | Cleartext remote login. Should be disabled — anything on the path can read the credentials. |
| 25 | SMTP | TCP | Server-to-server mail relay. Outbound 25 from a workstation is a spam or malware signal. |
| 53 | DNS | UDP + TCP | UDP for queries, TCP for large replies and zone transfers (AXFR). DNS over TLS is 853, DNS over HTTPS is 443. |
| 67, 68 | DHCP — server (67), client (68) | UDP | Broadcast address assignment. Watch for rogue servers and pool exhaustion. |
| 69 | TFTP | UDP | Trivial file transfer with no authentication. Used for device images and, by attackers, for tools. The transfer moves to a random high port after the first packet. |
| 80 | HTTP | TCP | Cleartext web. Also used for command-and-control that cannot be bothered with TLS. |
| 88 | Kerberos | TCP + UDP | Active Directory authentication. Kerberoasting and AS-REP roasting generate events around it. |
| 110 | POP3 | TCP | Mail retrieval. The encrypted version is POP3S on 995. |
| 123 | NTP | UDP | Time synchronisation. Accurate, consistent time is what makes log correlation possible. |
| 135 | MS RPC endpoint mapper | TCP | Tells a client which dynamic port a Windows RPC service is listening on. You will see 135 followed by a high port. |
| 137, 138, 139 | NetBIOS name / datagram / session | UDP, UDP, TCP | Legacy name resolution and SMB over NetBIOS. Noisy and risky across a network boundary. |
| 143 | IMAP | TCP | Server-side mail access. The encrypted version is IMAPS on 993. |
| 161, 162 | SNMP — agent (161), trap (162) | UDP | 161 is polled, 162 receives device-generated alerts. Version 1 and 2c community strings are cleartext. |
| 179 | BGP | TCP | Routing between networks. A hijack or a rogue peer shows up here. |
| 389 | LDAP | TCP + UDP | How Active Directory is queried. Enumeration and reconnaissance tools land here. |
| 443 | HTTPS | TCP (UDP for HTTP/3) | Web over TLS, and the most common place to hide command-and-control. |
| 445 | SMB (microsoft-ds) | TCP | Windows file sharing and IPC. Also lateral movement, ransomware propagation and NTLM relay. |
| 465 | SMTPS / submissions | TCP | Mail submission over implicit TLS. IANA registers 465 as submissions. |
| 514 | syslog | UDP (TCP also used) | Where devices and Unix hosts ship logs. IANA lists UDP 514 as syslog and TCP 514 as shell; the TLS version is 6514. |
| 587 | SMTP submission | TCP | Client mail submission, normally upgraded with STARTTLS. |
| 636 | LDAPS | TCP | LDAP over TLS. The alternative is 389 with StartTLS. |
| 993 | IMAPS | TCP | IMAP over TLS. |
| 995 | POP3S | TCP | POP3 over TLS. |
| 1433 | Microsoft SQL Server | TCP | Common database target. The SQL Browser service is UDP 1434. |
| 2049 | NFS | TCP + UDP | Unix file sharing. An exposed NFS share is a direct data-exposure finding. |
| 3260 | iSCSI | TCP | Block storage over IP. A storage network should never face the internet. |
| 3268, 3269 | AD Global Catalog — plain (3268), TLS (3269) | TCP | Forest-wide directory searches across Active Directory. |
| 3306 | MySQL / MariaDB | TCP | Frequently exposed to the internet by mistake. |
| 3389 | RDP (ms-wbt-server) | TCP (+ UDP) | Remote Desktop. A leading initial-access route when internet-facing. |
| 5432 | PostgreSQL | TCP | Common database target. |
| 5985, 5986 | WinRM — HTTP (5985), HTTPS (5986) | TCP | Remote Windows management, and a lateral-movement path. |
| 6379 | Redis | TCP | Often deployed with no authentication. |
| 8080 | HTTP alternate | TCP | Application servers, proxies and admin panels. |
| 8443 | HTTPS alternate | TCP | Administrative consoles, and sometimes command-and-control. |
| 9200 | Elasticsearch (convention) | TCP | The Elasticsearch HTTP API by convention. IANA registers 9200 as wap-wsp, so this one is a de-facto standard rather than an assignment. |
| 11211 | Memcached | TCP + UDP | Unauthenticated cache, and a well-known denial-of-service amplification vector. |
| 27017 | MongoDB | TCP | Frequently exposed with no authentication. |
| 49152–65535 | Ephemeral (client) ports | TCP/UDP | Client source ports. In a log, a high source port usually means that side started the conversation. |
Conventions versus assignments
Not every number you meet is an IANA assignment. Oracle Database has used 1521 for so long that everyone treats it as the Oracle port, but the registry lists 1521 as ncube-lm. Elasticsearch on 9200 and HTTPS-alternate on 8443 are conventions in the same way. Knowing which numbers are official and which are habits is the kind of detail that makes an answer sound like experience rather than a list.
Port numbers and transport protocols on this page were checked against the IANA Service Name and Transport Protocol Port Number Registry. Where a service is normally used on one transport but registered on both, the usual transport is shown first.
How to reason about a port you do not recognise
You will meet ports that are not on any list. The interviewer knows that. What they are watching for is whether you have a method.
1. Read the direction first
Who started the connection? An inbound connection to a low port means a service is being contacted. An outbound connection from an internal host to an external address means an internal host reached out, which is a very different story. Most of the meaning of a firewall line comes from direction, before the port.
2. Name the transport
A port number on its own is ambiguous. If you do not know whether the traffic is TCP or UDP, you cannot say what behaves normally. UDP is fire-and-forget and suits short request-and-reply exchanges; TCP has a handshake and connection state, which is why a long, stable TCP session on a port that normally carries quick queries is interesting.
3. Ask whether the port matches the behaviour
The number is a label, not a guarantee. Traffic on 53 that is large, constant and encrypted-looking is probably not ordinary DNS. A port that should carry short requests but holds a session open for hours is probably carrying something inside something else. When the label and the behaviour disagree, trust the behaviour.
4. Check the well-known ranges and the usual suspects
A low port is likely a service. A high port is likely a client — but a service is allowed to live on a high port, and malware often does, because high ports are less scrutinised and often allowed outbound. Ports such as 4444, 8080, 8443 and 1337 turn up again and again in attacker tooling, but so do ordinary applications, so treat them as a prompt to look closer rather than a conclusion.
5. Identify the process, not just the port
On the host, map the connection to the process that owns it: netstat -ano or Get-NetTCPConnection on Windows, ss -p or lsof -i on Linux. Knowing that the process is chrome.exe or svchost.exe or an unsigned binary in a temporary folder changes the answer entirely. The port tells you where to look; the process often tells you what you found.
6. Say what you do not know
A good answer to an unfamiliar port sounds like: I do not recognise this number, so I would check the direction and transport, see which process and host are involved, compare it with what normally happens here, and escalate if it does not fit. That is a better answer than a confident guess, because it is how the job is actually done.
What a port tells you in a log or firewall line
This is where the reference list earns its keep. Two examples come up more than any others in interviews.
Why outbound SMB 445 to the internet is a red flag
SMB is Windows file and printer sharing. It is designed to be used between machines on the same internal network, where the organisation controls both ends. A connection from an internal host out to a public address on 445 means one of two things: a misconfiguration that is leaking internal file-sharing traffic onto the internet, or an internal machine reaching a file share it should not be able to reach — for example, a host exfiltrating data to an attacker-controlled server, or a piece of malware that uses SMB because it is a fast way to copy files.
The direction is what makes it notable. Internal 445 between a client and a file server is routine. Outbound 445 to the public internet is not, and it should be blocked at the perimeter as a matter of course. A SOC seeing an allowed outbound 445 connection treats it as suspicious and works out who, what and why.
Why "it is on 443 so it is safe" is wrong
Port 443 carries TLS, so the contents of a 443 session are encrypted. That tells you nobody can read the payload in transit. It tells you nothing at all about whether the traffic is benign. Attackers put command-and-control on 443 precisely because it is encrypted, it blends into the enormous volume of ordinary web traffic, and it passes egress rules that only permit common ports.
To judge a 443 connection you look at everything except the port: the destination and its reputation, how recently the domain or certificate was registered, who issued the certificate, the size and timing of the traffic, which process on the host opened it, and whether the host has any business talking to that destination. Beaconing every 60 seconds with consistent packet sizes is not browsing. The port is the least informative part of the picture.
A short reading checklist
- Direction: who initiated the connection?
- Transport: TCP or UDP, and does the behaviour match?
- Port: expected for this host, or new?
- Process: what on the host owns the connection?
- Destination: internal or external, known or new, and how old is it?
- Pattern: one connection, or regular and repeated?
38 ports and services questions, with answers
Grouped roughly from easy to hard. Read each question, answer it out loud, then read the answer here. The gap between the two is your revision list.
Fundamentals interviewers assume you know
1. What is a port, and why does a computer need one?
A port is a 16-bit number, from 0 to 65535, that identifies which application on a host should receive a piece of traffic. The IP address gets the packet to the right machine; the port gets it to the right process on that machine. Together with the protocol and the IP address, a port forms a socket. A server listens on a fixed port, and each client picks a high-numbered source port of its own.
2. What is the difference between a listening port and an established connection?
A listening port means a process has bound to that port and is waiting for someone to connect — netstat shows LISTENING on Windows and ss or netstat shows LISTEN on Linux. An established connection means two hosts have completed the handshake and are actively exchanging data. An open port is not the same as an active connection, and a firewall line for a blocked attempt is not the same as a successful session.
3. What are the port ranges, and why do they exist?
Ports 0 to 1023 are the well-known, or system, ports, reserved for core services such as HTTP and DNS. Ports 1024 to 49151 are the registered, or user, ports, used by vendors and applications. Ports 49152 to 65535 are the dynamic, private or ephemeral ports, which clients use as their source port. The ranges exist so a client can almost always find a free port without colliding with a service.
4. What is the difference between TCP and UDP?
TCP is connection-oriented: it performs a three-way handshake, orders and acknowledges data, and retransmits what is lost. UDP is connectionless: it sends datagrams with no handshake and no delivery guarantee. TCP is used where completeness matters, such as HTTP, HTTPS, SMB and RDP. UDP is used where speed and low overhead matter, such as DNS queries, DHCP, NTP, SNMP, syslog and TFTP. The two are separate namespaces, so the same number can exist on both.
5. Can two services use the same port number?
Yes, in two ways. TCP and UDP are separate namespaces, so a service on TCP 53 and a service on UDP 53 do not clash. Within one protocol, a listening socket is bound to an IP address and a port, so two processes can listen on the same port on different IP addresses of the same host. Two processes cannot normally listen on the exact same IP and TCP port at once.
6. What does it mean when someone says a port is open?
It means something is listening and willing to accept a connection. A scanner sees three outcomes: open, when the host replies with a SYN-ACK; closed, when it replies with a reset; and filtered, when there is no reply at all because a firewall dropped the packet. You can check locally with netstat, ss or Get-NetTCPConnection, and remotely with a port scanner.
7. Why does the direction of traffic change what a port means?
The same number means different things depending on who started the conversation. Inbound to 3389 on a workstation means someone is offering Remote Desktop to that workstation. Outbound to 3389 from an internal host means that host is connecting to somebody else's Remote Desktop, which is how brute force and lateral movement look. Outbound SMB on 445 to a public address is a red flag, while internal 445 between a file server and a client is ordinary. Read the direction before the number.
8. What is an ephemeral port, and how do I spot one in a log?
An ephemeral port is the temporary high-numbered source port a client uses for a single conversation. In a log, the side with the low well-known port is usually the server and the side with a high port above about 49152 is usually the client. Be careful with replies, where the source port is the service. If both ports are high, the service is on a non-standard port, and the direction of the connection tells you which side started it.
Named ports and services
9. Which ports does FTP use, and why are there two?
FTP uses TCP 21 for the control channel, where the login and commands happen, and TCP 20 for the data channel in active mode, where the server connects back to the client. Passive mode, which is more common today, negotiates a random high port for data over the control channel. Both channels carry credentials and files in cleartext, which is why FTPS or SFTP should replace it.
10. What port does SSH use, and what does SSH on a non-standard port tell you?
SSH uses TCP 22 for an encrypted remote shell, file transfer with SCP or SFTP, and tunnelling. SSH on a port such as 2222 is a clue, not a verdict. It may be an administrator avoiding a noisy scan, or an attempt to slip past egress filtering that only allows common ports. Confirm what is actually running rather than assuming the port proves the service.
11. Why is Telnet on port 23 still asked about?
Telnet is TCP 23 and sends everything, including the username and password, in cleartext. It should be disabled on any modern system. It still comes up because older network devices and embedded systems run it, attackers use it against internet-of-things gear, and security teams use a Telnet client to test whether a mail or web port is responding. Seeing it in a log is a finding worth raising.
12. What is the difference between SMTP on 25, 587 and 465?
TCP 25 is classic SMTP, used for server-to-server relay and often blocked outbound by internet providers to fight spam. TCP 587 is the mail submission port, used by a mail client to hand a message to its own server, normally upgraded with STARTTLS. TCP 465 is submission over implicit TLS, sometimes called SMTPS, and IANA registers 465 under the name submissions. A burst of outbound 25 from a workstation rather than a mail server is a strong spam or malware signal.
13. When does DNS use UDP on 53, and when does it use TCP?
DNS queries normally go over UDP 53 because they are small and fast. TCP 53 is used for responses too large for one UDP datagram, for zone transfers between name servers with AXFR and IXFR, and for some DNSSEC responses. DNS has also moved onto other ports: DNS over TLS uses TCP 853 and DNS over HTTPS uses TCP 443. A SOC cares because DNS is one of the most abused protocols for tunnelling and command-and-control.
14. Explain DHCP 67 and 68 — which side is which?
DHCP runs over UDP. Port 67 is the server side, called bootps, and port 68 is the client side, called bootpc. The exchange is a broadcast four-step handshake — Discover, Offer, Request, Acknowledgement, remembered as DORA. A SOC watches for rogue DHCP servers and for starvation, where an attacker exhausts the address pool. IPv6 has its own equivalent on UDP 546 and 547.
15. What actually changes between HTTP 80 and HTTPS 443?
The web protocol is the same; what changes is that 443 wraps it in TLS. HTTP on TCP 80 sends requests, headers and cookies in cleartext, so anyone on the path can read and alter them. HTTPS on TCP 443 encrypts the payload and authenticates the server with a certificate, and 443 also carries HTTP over QUIC on UDP. The number itself does not make traffic safe, because an attacker can run any protocol, including command-and-control, over 443.
16. Why does a SOC analyst care about POP3 110 and IMAP 143?
TCP 110 is POP3 and TCP 143 is IMAP, the two protocols a mail client uses to read mail. POP3 typically downloads and removes mail from the server, while IMAP keeps mail synchronised on the server. The encrypted versions are POP3S on 995 and IMAPS on 993. They matter because a compromised account can be accessed over them, because attackers sometimes use IMAP to sync and steal a mailbox, and because brute-force or password-spray traffic against 143 or 993 is easy to spot.
17. What is NTP 123 for, and why does a SOC care about time?
NTP synchronises clocks and normally runs over UDP 123. A SOC cares because correlation depends on time: if two systems disagree by minutes, your timeline of an incident is wrong. Attackers also abuse NTP to amplify denial-of-service traffic, and unusual NTP behaviour on a host can be a sign of tunnelled traffic or a manipulated clock.
18. Explain NetBIOS 137, 138 and 139.
NetBIOS uses three ports. UDP 137 is the name service, which resolves NetBIOS names. UDP 138 is the datagram service, used for broadcast messages. TCP 139 is the session service, which carried SMB over NetBIOS before direct SMB arrived. Modern Windows uses SMB directly on TCP 445, so 137 to 139 are largely legacy. Seeing them crossing a network boundary is a sign of an old system or a misconfiguration worth investigating.
19. What is the difference between SNMP 161 and 162?
Both run over UDP. Port 161 is the SNMP agent that a management station polls for metrics and configuration. Port 162 is the trap receiver, so the device sends alerts to the manager on 162 without being asked. Versions 1 and 2c use community strings such as public and private, which travel in cleartext; version 3 adds authentication and encryption. SNMP is a favourite for device enumeration and can also be used for amplification attacks.
20. What is the difference between LDAP 389, LDAPS 636 and the Global Catalog on 3268 and 3269?
LDAP on TCP 389 is how directory services such as Active Directory are queried, and it can be upgraded to encryption with StartTLS. LDAPS on TCP 636 is LDAP wrapped in TLS from the start. The Global Catalog answers forest-wide searches on TCP 3268, with a TLS version on 3269. A SOC watches these ports because directory enumeration and reconnaissance tools generate distinctive query patterns against them.
21. What is SMB 445, and how is it different from 139?
SMB is the Windows file and printer sharing protocol, and port 445 carries it directly over TCP, registered by IANA as microsoft-ds. Port 139 carries SMB over the older NetBIOS session service. Direct SMB on 445 is what modern Windows uses. It matters because the same port is used for lateral movement, ransomware propagation and NTLM relay. SMB signing and SMB 3 encryption are the defences, and outbound 445 to the internet should be blocked.
22. What is syslog 514, and why does the transport matter?
Syslog is the standard way network devices and Unix hosts ship log messages to a collector, traditionally over UDP 514. The IANA registry lists UDP 514 as syslog and TCP 514 as shell. TCP is also widely used in practice because a datagram can be dropped silently, and it is defined in RFC 6587. The TLS version runs on TCP 6514. Traditional syslog is unauthenticated and unencrypted, so a sender can be spoofed, which is why production collectors are usually configured with TLS and a disk-backed queue.
23. What is RDP 3389, and why is it dangerous when internet-facing?
RDP is the Microsoft Remote Desktop protocol on TCP 3389, with UDP also used for some transports. It gives an interactive desktop, so anyone who gets in is effectively sitting at the machine. Internet-exposed RDP is a long-standing initial-access route: attackers scan for it, brute-force credentials, then move around as a normal user. In a SOC, watch for inbound 3389 from the internet, repeated failed logons, and RDP sessions from unusual sources or at unusual hours.
24. Which database ports should I know, and why?
The common ones are Microsoft SQL Server on TCP 1433, MySQL and MariaDB on TCP 3306, PostgreSQL on TCP 5432, MongoDB on TCP 27017, Redis on TCP 6379, Memcached on TCP and UDP 11211, and Elasticsearch on TCP 9200 as an industry convention. They matter because databases are where the data lives, and exposed or unauthenticated ones are a direct path to theft or remote code execution. A workstation opening a connection to 3306 or 5432 is unusual; a database server accepting connections from the internet is a finding.
Transport protocol questions
25. Why does the transport protocol matter as much as the port number?
The port identifies the service and the transport tells you how to read the traffic and what a firewall will see. UDP 53 and TCP 53 are different conversations with different behaviour and different risks. Saying DNS is port 53 without naming the transport is only half an answer, and an interviewer will notice. State the transport with the port, every time.
26. Which of these are TCP, UDP, or both: 22, 53, 123, 161, 443, 445 and 514?
SSH 22, HTTPS 443 and SMB 445 are TCP in normal use. SNMP 161 is UDP. DNS 53, NTP 123 and syslog 514 are normally UDP but are also used over TCP, which is why the honest answer names the usual transport and then the exception. For DNS it is large responses and zone transfers, for NTP a rarely used fallback, and for syslog reliability and the TLS variant.
27. What is Kerberos port 88, and why does it use both TCP and UDP?
Kerberos is the authentication protocol behind Active Directory and uses port 88 on both TCP and UDP. Small ticket requests fit in a UDP datagram, while larger tickets need TCP. A SOC watches 88 because attacks such as Kerberoasting, AS-REP roasting and pass-the-ticket all generate distinctive Kerberos events, and because a spike in failed Kerberos requests can be a password-spray attempt.
Reading a port in a log or firewall line
28. In a firewall log you see an internal host connecting out to a public IP on port 445. What do you do?
Treat it as suspicious. SMB on 445 belongs on the internal network, and outbound 445 to the internet is unusual in almost every environment. Check how often it happens, which process on the host made the connection, whether the destination is newly seen and where it is registered, and whether the host shows other signs of compromise. Confirm the rule that allowed it and whether it should be blocked.
29. A colleague says the traffic is on 443, so it is encrypted and safe. Why is that wrong?
Encryption hides the contents; it does not verify intent. Attackers routinely run command-and-control over TLS on 443 precisely because it blends into normal web traffic and passes many egress rules. What matters is the destination, the certificate, the volume and timing of the traffic, the process making the connection, and whether the host is newly talking to that destination. Encrypted is not the same as trustworthy.
30. You see an internal host querying 8.8.8.8 on port 53 constantly. Is that suspicious?
On its own, no. That is a public DNS resolver and steady queries to it are ordinary. It becomes interesting when the host is a server that should use an internal resolver, when the query rate is far above normal, when queries go only to one unusual external resolver, or when the queries are long or oddly encoded, which points to DNS tunnelling. Judge it against what that host normally does.
31. A log shows a connection stuck in SYN_SENT with no reply. What does that tell you?
It means the host sent a SYN and never received a SYN-ACK. The destination dropped the packet, a firewall blocked it, or the host is unreachable. Repeated SYN_SENT to many destinations is how a port scan looks when the scanner is filtered: it keeps trying and keeps getting nothing back. A single SYN_SENT is usually just a service that is down or blocked.
32. One host is connecting to many ports on many hosts in a short window. What is that?
The shape of a port scan. The detail tells you the type: a SYN scan to many ports leaves many incomplete handshakes, a connect scan completes them, and a sweep hits one port across many hosts. The next questions are whether the host is allowed to scan, whether it is a vulnerability scanner, and whether anything on the scanned hosts responded. Scanning is not automatically an attack, but it is a lead.
33. You see a source or destination port of 0 in a log. What does that mean?
Port 0 is reserved and is not a real service port. If you see it, suspect malformed traffic, a spoofed packet, or a log or parsing problem rather than a service on port 0. A value above 65535 likewise means the log is corrupted or generated by a tool. Do not build a detection on a value that cannot exist.
Scenario questions
34. A host is beaconing to an external IP on port 8443 every 60 seconds. What do you check?
Start with the pattern: regular intervals and similar packet sizes are the signature of automated command-and-control rather than a person browsing. Then check which process on the host is making the connection, what the destination IP and domain are and when they were registered, whether the certificate is valid and who issued it, what else the host did around the same time, and whether other hosts talk to the same destination. Port 8443 is common for administrative consoles and also for command-and-control, so the port alone settles nothing.
35. An alert fires for inbound RDP 3389 from a public IP to an internal server. What are your next steps?
Find out whether the logon succeeded. If it failed, look at how many attempts and whether other accounts were tried, then confirm the server should not be exposed at all. If it succeeded, treat it as a possible compromise: identify the account and source, check what happened in the session, look for persistence and new accounts, and start containment. Either way, the exposure itself needs fixing.
36. A workstation starts opening SMB 445 connections to other workstations. What does that suggest?
Workstations rarely talk SMB to each other, so this is unusual and worth investigating. It can be lateral movement or worm-like propagation such as a ransomware outbreak, or it can be a legitimate management tool. Check which process is initiating it, whether authentication succeeded, which shares were accessed, and whether the pattern spreads from host to host. Contain first if the spread is ongoing.
37. A server that should only serve web traffic is now listening on 3389 and 445. What do you check?
Unplanned listening services are a classic sign of something installed or enabled on the host. Confirm what is actually bound to those ports and which process owns it, when it started, whether it is set to run at boot, and who made the change. Check whether the same host opened outbound connections around the same time. Compare it against a known-good baseline of what that server should be running.
38. A host connects outbound to an unknown server on port 4444. What could that be?
Port 4444 is the long-standing default listener for the Metasploit handler, so it is a well-known flag for a possible reverse shell or command-and-control. It is also used legitimately by some software, so confirm before you conclude. Check the process, the destination, whether the connection is persistent and regular, and what the host did just before it started. A single outbound connection to 4444 from a user workstation deserves a proper look.
This page is a free sample
This is one topic from a paid course of 55 sessions. The full course walks the same way through networking, Windows and Linux, Active Directory, SIEM and log integration, detection, incident response and interview practice — and it will not let you skip the parts you find hard. Every session ends with a quiz, and you need 80% to unlock the next one.
The whole thing is ₹100, once, for lifetime access. No renewals and no upsells. If this page helped, the rest is built the same way.
Learn the port. Then learn what it means.
Naming the port is the easy half. The course takes it from there — what the traffic means, what an attacker does with it, and how you would spot it in a log.
See the curriculum