Disabling unused modules is a proactive control that can reduce the attack surface of a web server, by minimizing the number of potential entry points or vulnerabilities that an attacker can exploit. Disabling unused modules can also improve the performance and stability of the web server, by freeing up resources and reducing complexity.