QuestionQ37

Security and disaster recovery

A company's IDS detected outbound traffic from one of its web servers over port 389 to an external address. The server hosts websites only. The company's SOC administrator has asked a technician to harden this server. Which of the following is the BEST way to fulfill this request?

Explanation

Port 389 is commonly used for LDAP, not normal web hosting. A web-only server should not require outbound LDAP traffic to an external address, so disabling port 389 removes an unnecessary and potentially malicious communication path.

Community Discussion

No comments yet. Be the first to start the discussion!