Skip Navigation

IIST-SV-000158: Remove unspecified file extensions

Unspecified file extensions on a production IIS 10.0 web server must be removed.
To check compliance with IIST-SV-000158, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Double-click the
    ISAPI and CGI restrictions
    icon.
  4. Click
    Edit Feature Settings
    .
  5. Verify that
    Allow unspecified CGI modules
    and
    Allow unspecified ISAPI modules
    are not selected.
If
Allow unspecified CGI modules
or
Allow unspecified ISAPI modules
is selected, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Double-click the
    ISAPI and CGI restrictions
    icon.
  4. Click
    Edit Feature Settings
    .
  5. Deselect
    Allow unspecified CGI modules
    and
    Allow unspecified ISAPI modules
    .
  6. Click
    OK
    .