ExamRange

CND (312-38) Network Defense Simulation

Core Network Protocol Analysis

Learn to differentiate between Well-Known, Registered, and Dynamic port ranges to identify unauthorized service exposure and refine firewall filtering policies.

Network Scenario

As a Network Security Analyst, you are auditing the perimeter firewall of an enterprise DMZ. The DMZ hosts several critical services including a Web Server (HTTP/S), an Email Gateway (SMTP), and a Secure File Transfer (SFTP) server.

DMZ Segment: 172.16.10.0/24
Policy: Strict Inbound Filtering
Objective: Ensure only standard administrative and user services are reachable from the public internet.

Traffic & Logs

// Firewall Log Snippet - Inbound Traffic
[2023-10-27 14:02:11] SRC: 198.51.100.45 DST: 172.16.10.10 PROTO: TCP SPT: 54221 DPT: 80 ACTION: ALLOW
[2023-10-27 14:02:15] SRC: 198.51.100.45 DST: 172.16.10.10 PROTO: TCP SPT: 54222 DPT: 443 ACTION: ALLOW
[2023-10-27 14:02:22] SRC: 203.0.113.88 DST: 172.16.10.25 PROTO: TCP SPT: 49120 DPT: 25 ACTION: ALLOW
[2023-10-27 14:03:01] SRC: 45.33.12.112 DST: 172.16.10.10 PROTO: TCP SPT: 33211 DPT: 8080 ACTION: DENY
[2023-10-27 14:03:05] SRC: 45.33.12.112 DST: 172.16.10.10 PROTO: TCP SPT: 33212 DPT: 3389 ACTION: DENY
// IDS Alert: Port Scan Detected on Well-Known Ranges from 45.33.12.112

Question

What is the range for well known ports?