Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SY0-501 topic 1 question 16 discussion

Actual exam question from CompTIA's SY0-501
Question #: 16
Topic #: 1
[All SY0-501 Questions]

A security analyst wishes to increase the security of an FTP server. Currently, all traffic to the FTP server is unencrypted. Users connecting to the FTP server use a variety of modern FTP client software.
The security analyst wants to keep the same port and protocol, while also still allowing unencrypted connections. Which of the following would BEST accomplish these goals?

  • A. Require the SFTP protocol to connect to the file server.
  • B. Use implicit TLS on the FTP server.
  • C. Use explicit FTPS for connections.
  • D. Use SSH tunneling to encrypt the FTP traffic.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Stefanvangent
Highly Voted 4 years, 8 months ago
The key part in this question is: "MODERN FTP client software." Explicit FTPS is the newer method of FTPS transfer and has generally overtaken implicit FTPS use, with the exception of "legacy" systems. When explicit FTPS is used, a traditional FTP connection is established on the same standard port as FTP. Once the connection is made (before login), a secure SSL connection is established via port 21.
upvoted 33 times
...
zaws
Highly Voted 4 years, 3 months ago
The real key is "The security analyst wants to keep the same port and protocol." TLS/SSL Explicit mode usually uses the same port as Plain (unsecure) mode. TLS/SSL Implicit mode requires dedicated port. TLS/SSL Implicit mode cannot be run on the same port as TLS/SSL Explicit mode. ... The TLS/SSL protocol is the same in both Explicit and Implicit mode.
upvoted 10 times
...
Dragi
Most Recent 3 years ago
implicit 990 explicit 21 control traffic and 20 data traffic
upvoted 6 times
...
dinosan
4 years, 1 month ago
Explicit FTPS is the newer method of FTPS transfer and has generally overtaken implicit FTPS use, with the exception of legacy systems. When explicit FTPS is used, a traditional FTP connection is established on the same standard port as FTP. Once the connection is made (before login), a secure SSL connection is established via port 21. Source: https://www.ftptoday.com/blog/explicit-ftps-vs-implicit-ftps-what-you-need-to-know
upvoted 7 times
...
Cyber06
4 years, 6 months ago
The Answer is C. Explicit FTPS uses port 21 while implicit FTPS uses port 990.
upvoted 9 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...