A network administrator is reviewing a production web server and observes the following output from the netstat command. Which of the following actions should the network administrator take to harden the security of the web server?
Disable the unused ports.
Disabling unused ports is a fundamental security measure that reduces the attack surface of a web server by preventing unauthorized access through ports that are not actively in use. This practice minimizes potential vulnerabilities and helps safeguard the server from various network-based attacks.
This option directly addresses security by limiting access points to the server. Unused ports can be exploited by attackers, so disabling them is a proactive step in reducing vulnerabilities and enhancing overall security posture.
While enforcing access control lists (ACLs) is an important security measure, it typically applies to controlling traffic flow and permissions for users or devices accessing the network. However, it does not directly reduce the number of active ports, which is crucial for hardening the security of the web server.
Content filtering focuses on controlling the type of content that can be transmitted or received by the web server, which is relevant for preventing malicious content but does not specifically address the security risks associated with open ports.
Setting up a screened subnet provides an additional layer of network security and can help isolate servers from direct exposure to the internet. However, it does not directly affect the security of ports on the web server itself and may involve more complex network architecture adjustments than simply disabling unused ports.
To harden the security of a production web server, the most effective immediate action is to disable unused ports. This minimizes the risk of unauthorized access through inactive services, thereby enhancing the server's overall security. While other options like ACLs, content filtering, and screened subnets contribute to a secure environment, they do not directly address the vulnerabilities posed by open ports as effectively as disabling them.
Related Questions
View allA company's network is experiencing high levels of suspicious network...
Which of the following is a characteristic of the application layer?
Users are reporting latency on the network. The network engineer notes...
Users report latency with a SaaS application. Which of the following s...
A network administrator is configuring a wireless network with an ESSI...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations