Common Port Numbers Cheat Sheet for CompTIA A+, Network+, and Security+

Port numbers are how a single computer runs many network services at once. When a packet arrives, the destination port tells the operating system which application should handle it. Every CompTIA exam — A+, Network+, and Security+ — expects you to recognize the common well-known ports on sight, because firewall rules, troubleshooting, and security analysis all depend on them. This cheat sheet lists the ports you must memorize, explains what each one does, and gives you memory tips and free practice questions.

What is a port number?

A port number is a 16-bit value from 0 to 65535 that identifies a specific service or conversation on a host. Combined with an IP address, it forms a network socket (IP:port). The Internet Assigned Numbers Authority (IANA) divides ports into three ranges. Well-known ports (0–1023) are assigned to common services like HTTP and DNS. Registered ports (1024–49151) are used by applications such as databases and custom services. Dynamic or ephemeral ports (49152–65535) are chosen by the operating system for the client side of a connection.

Port numbers reference table

PortProtocolTransportUse
20 / 21FTPTCPFile Transfer Protocol — data (20) and control (21)
22SSHTCPSecure Shell — encrypted remote command-line access
23TelnetTCPUnencrypted remote access (legacy)
25SMTPTCPSimple Mail Transfer Protocol — sending outbound email
53DNSTCP/UDPDomain Name System — name-to-IP resolution
67 / 68DHCPUDPDynamic Host Configuration Protocol — IP assignment
69TFTPUDPTrivial FTP — lightweight file transfer (PXE, configs)
80HTTPTCPHypertext Transfer Protocol — unencrypted web
110POP3TCPPost Office Protocol v3 — download email
123NTPUDPNetwork Time Protocol — clock synchronization
143IMAPTCPInternet Message Access Protocol — sync email
161 / 162SNMPUDPSimple Network Management Protocol — monitoring (162 = traps)
389LDAPTCPLightweight Directory Access Protocol — directory queries
443HTTPSTCPHTTP Secure — encrypted web over TLS
445SMBTCPServer Message Block — Windows file/printer sharing
465SMTPSTCPSMTP over TLS (implicit)
587SMTP submissionTCPAuthenticated client email submission over TLS
636LDAPSTCPLDAP over TLS
993IMAPSTCPIMAP over TLS
995POP3STCPPOP3 over TLS
1723PPTPTCPPoint-to-Point Tunneling Protocol — legacy VPN
1701L2TPUDPLayer 2 Tunneling Protocol — VPN tunneling
3389RDPTCPRemote Desktop Protocol — Windows remote desktop
3306MySQLTCPMySQL / MariaDB database
1433MS SQLTCPMicrosoft SQL Server database
8080HTTP altTCPAlternate HTTP port (proxies, dev servers)

TCP vs UDP at a glance

TCP is connection-oriented and reliable — it establishes a session with a three-way handshake, orders packets, and retransmits lost data. Use it where correctness matters: web, email, file transfer, and remote desktop. UDP is connectionless and fast with no delivery guarantee, which makes it ideal for DNS lookups, DHCP, NTP, and streaming. Security+ questions sometimes ask which protocol a firewall rule must match, so knowing whether a service runs over TCP or UDP is part of the answer.

Memory tips

  • Web pair: 80 is HTTP, 443 is HTTPS. "Add a 3 for secure" doesn't help, but remember HTTPS = HTTP + TLS on 443.
  • Email story: 25 sends (SMTP), 110 downloads (POP3), 143 syncs (IMAP). The secure mail ports end in 3 and 5: 993 (IMAPS) and 995 (POP3S), while 587 is modern authenticated submission.
  • Remote access: 22 is SSH (secure), 23 is Telnet (the insecure legacy one, one number higher), and 3389 is RDP (Windows remote desktop).
  • Secure pattern: many secure variants land in the 400s and 900s — 443, 465, 636, 993, 995. Spotting that pattern speeds recall.
  • Management: 161/162 is SNMP (monitoring), and 123 is NTP (think "1-2-3, on the clock").

Try 3 free sample questions

Questions are visible below. Pick an answer to reveal the correct one and the explanation.

Q1.An administrator needs encrypted remote command-line access to a Linux server. Which port should be allowed through the firewall?

Q2.Which protocol uses port 53?

Q3.A secure web application is being deployed. Which port should it listen on for HTTPS traffic?

Practice this free on CertiTom

Create a free account to drill unlimited practice questions on this topic across A+, Network+, and Security+. Pro members also get the hands-on Port-to-Protocol Mapping performance-based lab (Network+) — drag-and-drop practice that mirrors the real exam.

Frequently asked questions

What are the most important CompTIA port numbers to memorize?

For A+, Network+, and Security+ you should know 22 (SSH), 53 (DNS), 80 (HTTP), 443 (HTTPS), 25 (SMTP), 3389 (RDP), and the email ports 110 (POP3), 143 (IMAP), 993 (IMAPS), and 995 (POP3S). These appear repeatedly on all three exams.

Are these ports TCP or UDP?

Most are TCP, but DNS (53) uses both, and DHCP (67/68), TFTP (69), NTP (123), and SNMP (161/162) use UDP. Knowing the transport protocol matters for firewall rules and for Security+ questions about which traffic a rule will match.

Why do secure versions of protocols use different ports?

Adding TLS to a protocol historically meant moving to a new well-known port so clients could request the secure service explicitly — for example 993 for IMAPS and 995 for POP3S. Modern mail submission uses 587 with STARTTLS instead of a separate secure port, which is why both patterns appear on the exam.

Is this port numbers cheat sheet free to use?

Yes. This guide is free and requires no login. You can also practice unlimited CompTIA port-number questions for free with a CertiTom account, and Pro members get a drag-and-drop Port-to-Protocol Mapping lab.