If the internal website is bound to the company's second-level domain name, is it not secure?

for example, the company website is A.com, and there is a crm management system inside
. Is it easy to cause attacks and not very secure if you bind crm.A.com,?
is it accessed directly through ip? Or change to another domain name

Mar.16,2021

if you bind a second-level domain name directly, then what if is scanned.

since it is an intranet, you can reverse it directly. The easiest way to do this is to change to hosts , or Nginx and so on.

Menu