Memory hook: Resolve the name, obtain the lease, trust the clock.
Must remember
| Service | Conventional port(s) |
|---|---|
| FTP / SSH-SFTP / Telnet | TCP 21 control (FTP data varies) / 22 / 23. |
| SMTP / submission | TCP 25 / 587; implicit TLS submission commonly 465. |
| DNS | UDP and TCP 53. |
| DHCPv4 / DHCPv6 | UDP 67 server, 68 client / 547 server, 546 client. |
| HTTP / HTTPS | 80 / 443; HTTP/3 uses QUIC over UDP 443. |
| POP3 / IMAP | TCP 110 / 143; implicit TLS 995 / 993. |
| SNMP queries / traps | Usually UDP 161 / 162. |
| LDAP / LDAPS | 389 / 636. |
| SMB / RDP | TCP 445 / TCP and UDP 3389. |
| NTP / SIP | UDP 123 / commonly 5060, TLS 5061. |
Ports are conventions, not proof of application identity. Secure FTP (SFTP over SSH) differs from FTP with TLS (FTPS).
DNS A/AAAA map names to IPv4/IPv6; CNAME aliases another name; MX specifies mail exchangers; NS delegates authoritative service; PTR supports reverse lookup; TXT carries text used by policies and verification. A resolver asks authoritative servers and caches answers according to TTL. DNSSEC authenticates signed DNS data; it does not encrypt ordinary DNS queries. Encrypted DNS protects the resolver connection through its selected protocol.
DHCPv4 commonly follows Discover, Offer, Request, Acknowledge. Scopes define pools, options, exclusions and reservations. A relay forwards requests across routed boundaries. Exhausted pools, rogue servers, wrong options and blocked relay paths produce different symptoms. Reservations provide predictable leases, not static manual configuration on the host.
NTP synchronizes time broadly; PTP supports more precise timing in suitable networks; NTS adds authenticated security to NTP. Time matters for logs, certificates and ticket-based authentication.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Name resolves to wrong address | Check authoritative record, cached answer, TTL and split-DNS view. |
| Clients across router cannot obtain leases | Inspect DHCP relay and server scope. |
| Need trustworthy signed DNS answers | DNSSEC; use separate transport protection if confidentiality is required. |
Traps
- DNS can use TCP, not only UDP.
- A DHCP reservation does not prevent every rogue device from using an address.
Active recall
1. SSH and SFTP normally use which port?
TCP 22.
2. What does MX identify?
A mail exchanger for a domain.
3. Why is a DHCP relay needed?
Clients’ local discovery broadcasts do not ordinarily traverse routers.
4. Does DNSSEC hide queried names?
No. It provides authenticity/integrity, not query confidentiality.
5. Why might authentication fail when networking works?
Clock skew, certificates or ticket lifetimes can still invalidate authentication.