An organization has a policy that requires servers to be dedicated to one function and unneeded services to be disabled. Given the following output from an Nmap scan of a web server: Which of the following ports should be closed?
"servers to be dedicated to one function..." http/s and SQL are two functions. I will select D, but agree with folks that the question is horribly written, and the person who wrote it was most likely drunk.
question asks for a "WEB SERVER", so you may need to use FTP to download and upload files. Also, http and https are must for web server. Do not think it like http is not secure, so it should be closed. No, this is not how the system works in real life. HTTP and HTTPS are used by companies by providing reliable secure configurations on HTTP. There is one port left 1433 SQL DATABASE server. You do not need that on web server. Remember, you may need FTP on web server when you are dealing with files download/upload.
A SQL database shouldn't be on the server if the goal is to dedicate a server to one function. Also, it's generally not correct to expose a sql server port, if it's being used on the host.
Since the sole purpose of this server is to deliver web services, insecure port 1433 should be closed. I could also make a case for closing insecure port 21.
If the server is dedicated to one function (web server) and unneeded services are
disabled, then port 21 should be closed, because FTP is not necessary for a web server and could pose a
security risk if exploited. Port 80, port 443, and port 1433 are ports that are needed for a web server, because
they are used for HTTP, HTTPS, and SQL Server respectively. Reference: https://www.ssh.com/ssh/port
The questions says one function and unneeded services. Port 80 is irrelevant when port 443 is available. 1433 and 21 could be a backend server that webserver is connected to
Based on the organization's policy that requires servers to be dedicated to one function and unneeded services to be disabled, if I have to choose only one port to be closed based on the given Nmap scan output, I would recommend closing port 1433/TCP (SQL) if it is not required for the web server's intended function.
Clearly B. Question states we need to basically have one port per service, and the rest disabled. 1433 is the only port for SQL opened on this server, but why would we have both HTTP and HTTPS open? Close port 80, job done.
D. The server is dedicated as a web server (function) and the unneeded service to be disabled is 1433(sql). This is directly based of the question itself.
You can have separate server for databasing (which is often advisable), but you'll most likely need FTP for file transfers. The web-server is where you store all the necessary files (including HTML contents), after all, and file-transfer protocols are the most efficient avenue.
As they do not say what type server it is, we have to assume port 21 should be closed because the other ports would all be required to support either a webserver or a database server.
Based on the information provided, it is not possible to determine whether the organization should close any of the ports. However, if the policy of the organization is to dedicate servers to one function and to disable unneeded services, then it is likely that some of these ports should be closed.
In this case, assuming that the server is intended to be a web server, port 21 (FTP) and port 1433 (Microsoft SQL Server) are likely not necessary and should be closed. Port 80 and port 443 are necessary for web traffic, and should be left open. However, it is important to ensure that only necessary services are running on these ports, and that they are properly secured to reduce the risk of cyber attacks. - ChatGPT
This section is not available anymore. Please use the main Exam Page.CS0-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
MortG7
Highly Voted 2 years, 6 months agoSolventCourseisSCAM
Highly Voted 2 years, 6 months agofuzzyguzzy
Most Recent 5 months agoLearner213
5 months, 1 week agom025
1 year, 4 months agokmordalv
1 year, 6 months agoskibby16
1 year, 6 months agoattesco
1 year, 10 months agoDerekM
1 year, 11 months agouday1985
2 years agoJoInn
2 years agoJokerRWild
2 years ago2Fish
2 years, 2 months agoOrean
2 years, 2 months agoDrVoIP
2 years, 2 months agoDrVoIP
2 years, 2 months agoaisling
2 years, 3 months ago