Rule ID
SV-280948r1197218_rule
Version
V1R1
CCIs
If the system is not a Domain Name Server (DNS), it should not have a DNS server package installed to decrease the attack surface of the system.
Verify RHEL 10 does not have a DNS package installed with the following command: $ sudo dnf list --installed unbound Error: No matching Packages to list If the "unbound" package is installed, and the information system security officer lacks a documented requirement for a DNS, this is a finding.
Configure RHEL 10 to not have the unbound package installed with the following command: $ sudo dnf -y remove unbound