Why should the security analyst disable/remove unnecessary isapi filters? to defend against jailbreaking to defend against social engineering attacks to defend against wireless attacks to defend against webserver attacks?
The security analyst should disable unnecessary ISAPI filters for all of the above reasons. ISAPI filters can be used to essentially open technological gateways. Thus, they can be used to open items that have already been cued as "access denied", and allow hackers to enter into web spaces that are intended to be confidential.