# Cis Ubuntu1604 V200 2 1 7

> Ensure NFS is not installed

- Skill: `cyberstrikeus/cis-ubuntu1604-v200-2-1-7` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-2-1-7`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu1604-v200-2-1-7/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu1604-v200-2-1-7

---


# 2.1.7 Ensure NFS is not installed (Automated)

## Description

The Network File System (NFS) is one of the first and most widely distributed file systems in the UNIX environment. It provides the ability for systems to mount file systems of other servers through the network.

## Rationale

If the system does not export NFS shares or act as an NFS client, it is recommended that these services be removed to reduce the remote attack surface.

## Audit Procedure

### Command Line

Run the following command to verify nfs is not installed:

```bash
dpkg -s nfs-kernel-server | grep -E '(Status:|not installed)'
```

## Expected Result

```
dpkg-query: package 'nfs-kernel-server' is not installed and no information is available
```

## Remediation

### Command Line

Run the following command to remove nfs:

```bash
apt purge nfs-kernel-server
```

## Default Value

nfs-kernel-server is not installed on minimal server installations.

## References

1. CIS Controls v7 - 9.2 Ensure Only Approved Ports, Protocols and Services Are Running

## Profile

- Level 1 - Server
- Level 1 - Workstation

