CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security engineer is tasked with implementing server hardening best practices across a fleet of Linux servers. The organization's policy mandates that all unnecessary services must be disabled, and the attack surface minimized. Which of the following commands would be MOST effective in identifying all open network ports and the services listening on them to inform the hardening process?
- Aiptables -L -n -v
- Bps aux
- Cnetstat -tulnp
- Dls -l /etc/services
Show answer & explanationAnswer & explanation
Correct answer: C. netstat -tulnp
The `netstat -tulnp` command is specifically designed to list all active network connections, including listening sockets (TCP and UDP), show process IDs (PIDs) and program names associated with each socket, and display numeric addresses instead of resolving hostnames. This provides a comprehensive view of open ports and their corresponding services, which is crucial for identifying and disabling unnecessary services during server hardening.
Why the other options are wrong
- A. `iptables -L -n -v` displays the current iptables firewall rules, which show what traffic is allowed or denied, but not necessarily what services are actively listening.
- B. `ps aux` lists all running processes but does not directly show which processes are listening on network ports.
- D. `ls -l /etc/services` lists the `/etc/services` file, which maps port numbers to service names, but does not show currently active or listening services.
netstat
The `netstat` command (network statistics) is a command-line network utility that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics.
- Used for network troubleshooting and performance monitoring.
- Can show listening ports and established connections.
- Various flags (e.g., -t, -u, -l, -n, -p) customize output.
- Crucial for identifying active services during hardening.
Memory trick: Netstat Knows Every Open Port and Process