Well-known ports
TCP and UDP port numbers 0 to 1023, assigned by IANA to standard services; a port shows the service expected on a connection, not the traffic actually carried.
A port number identifies which service on a host a TCP or UDP segment is meant for. RFC 6335 divides the 65,536 possible ports into three ranges. System ports, commonly called well-known ports, run from 0 to 1023 and are assigned by IANA to standard services; HTTPS, for example, is assigned 443. User or registered ports run from 1024 to 49151, and dynamic or private ports, 49152 to 65535, are intended for temporary use, commonly by clients. On many operating systems, only a privileged process may listen on a well-known port.
The security point is that a port is a convention, not an identity. Any service can listen on any port, and an attacker who needs to leave a network commonly tunnels traffic over a port the firewall already allows. A packet-filtering firewall that decides on port numbers alone is therefore trusting a label. A next-generation firewall inspects the traffic to identify the application actually in use. Moving a service to an unusual port is obscurity, not a control. Closing unneeded ports reduces the attack surface.
Exam relevance: questions in this area tend to turn on what a port number can and cannot prove. Candidates are expected to know the three ranges, and to recognise that allowing or blocking by port does not establish which application is really crossing the boundary.