Cis Ubuntu1604 V200 2 1 8

Ensure DNS Server is not installed

cyberstrikeus Updated

File contents

2.1.8 Ensure DNS Server is not installed (Automated)

Description

The Domain Name System (DNS) is a hierarchical naming system that maps names to IP addresses for computers, services and other resources connected to a network.

Rationale

Unless a system is specifically designated to act as a DNS server, it is recommended that the package be deleted to reduce the potential attack surface.

Audit Procedure

Command Line

Run the following command to verify DNS server is not installed:

dpkg -s bind9 | grep -E '(Status:|not installed)'

Expected Result

dpkg-query: package 'bind9' is not installed and no information is available

Remediation

Command Line

Run the following commands to disable DNS server:

apt purge bind9

Default Value

bind9 is not installed on minimal server installations.

References

  1. CIS Controls v7 - 9.2 Ensure Only Approved Ports, Protocols and Services Are Running

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-2-1-8 commit 915751eae0

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-2-1-8