312-50V9 · Question #536
What ports should be blocked on the firewall to prevent NetBIOS traffic from not coming through the firewall if your network is comprised of Windows NT, 2000, and XP?(Choose all that apply.
The correct answer is B. 135 C. 139 E. 445. Ports 135, 139, and 445 are the key ports associated with NetBIOS and Windows SMB file-sharing services and must be blocked to prevent related traffic from traversing the firewall.
Question
What ports should be blocked on the firewall to prevent NetBIOS traffic from not coming through the firewall if your network is comprised of Windows NT, 2000, and XP?(Choose all that apply.
Options
- A110
- B135
- C139
- D161
- E445
- F1024
How the community answered
(44 responses)- A2% (1)
- B75% (33)
- D14% (6)
- F9% (4)
Why each option
Ports 135, 139, and 445 are the key ports associated with NetBIOS and Windows SMB file-sharing services and must be blocked to prevent related traffic from traversing the firewall.
Port 110 is POP3, used for incoming email retrieval from a mail server, and is unrelated to NetBIOS or Windows file sharing services.
Port 135 is used by Microsoft RPC endpoint mapper and DCOM, which underpin NetBIOS-dependent Windows networking and remote service communication.
Port 139 is the NetBIOS Session Service port used by Windows NT, 2000, and XP for SMB-based file and printer sharing transported over NetBIOS.
Port 161 is SNMP, used for network device monitoring and management, and has no relationship to NetBIOS or Windows file sharing traffic.
Port 445 is used by SMB Direct (CIFS), which Windows 2000 and XP introduced for file sharing without requiring NetBIOS, and is a primary attack vector that must also be blocked.
Port 1024 is not a defined NetBIOS port - it falls in the dynamic/private port range and is not specifically associated with NetBIOS or SMB services.
Concept tested: NetBIOS and SMB port numbers for firewall filtering
Source: https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/direct-hosting-of-smb-over-tcpip
Topics
Community Discussion
No community discussion yet for this question.