# Cis Ubuntu1604 V200 2 1 10

> Ensure HTTP server is not installed

- Skill: `cyberstrikeus/cis-ubuntu1604-v200-2-1-10` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-2-1-10`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu1604-v200-2-1-10/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu1604-v200-2-1-10

---


# 2.1.10 Ensure HTTP server is not installed (Automated)

## Description

HTTP or web servers provide the ability to host web site content.

## Rationale

Unless there is a need to run the system as a web server, it is recommended that the package be deleted to reduce the potential attack surface.

## Audit Procedure

### Command Line

Run the following command to verify apache is not installed:

```bash
dpkg -s apache2 | grep -E '(Status:|not installed)'
```

## Expected Result

```
dpkg-query: package 'apache2' is not installed and no information is available
```

## Remediation

### Command Line

Run the following command to remove apache:

```bash
apt purge apache2
```

## Default Value

apache2 is not installed on minimal server installations. Several httpd servers exist and can use other service names. apache2 and nginx are example services that provide an HTTP server. These and other services should also be audited.

## References

1. CIS Controls v7 - 9.2 Ensure Only Approved Ports, Protocols and Services Are Running

## Profile

- Level 1 - Server
- Level 1 - Workstation

