CompTIA Server+ SK0-005 Practice Question
A vulnerability scan reports that TCP port 445 on a Windows Server 2022 fileserver is reachable from the public Internet, even though company policy states that only HTTPS (TCP 443) should be exposed externally. Internal users still must map network drives to the server. Which action is the MOST appropriate first step to troubleshoot and remediate this open-port security issue?
Stop or disable the Server (LanmanServer) service on the Windows host.
Apply the latest cumulative Windows security updates to the server.
Add a deny rule on the perimeter or host firewall that blocks inbound TCP 445 traffic from untrusted networks.
Remove the server's host-A record from external DNS zones.