An organization has the following policies:

* Services must run on standard ports.

* Unneeded services must be disabled.

The organization has the following servers:

* – web server

* – database server

A security analyst runs a scan on the servers and sees the following output:

Which of the following actions should the analyst take?
A . Disable HTTPS on
B. Disable IIS on
C. Disable DNS on
D. Disable MSSQL on
E. Disable SSH on both servers.

Answer: E


SSH stands for Secure Shell, which is a protocol that allows remote access and administration of a server. If the organization has a policy that services must run on standard ports and unneeded services must be disabled, then SSH should be disabled on both servers, because it runs on port 22, which is not a standard port for a web server or a database server, and it is not needed for those servers to function properly. Disabling HTTPS on, disabling IIS on, disabling DNS on, or disabling MSSQL on are not appropriate actions, because they would affect the functionality of the web server or the database server and violate the organization’s policy of running services on standard ports.

Reference: https://www.ssh.com/ssh/port

