Windows enables this port by default in many configurations to support "Plug and Play" networking features.

If the host does not need to advertise itself (e.g., a dedicated database server or web server), you can disable the service entirely.

Port 5357 is a functional necessity for modern Windows networking but a luxury for standalone or public-facing servers. If you aren't sharing printers or searching for network devices, To help you secure your specific setup, could you tell me: Is this scan result from a home PC or a company server ? Are you seeing this port open on a public IP or a local IP ? Do you rely on network printers or shared drives daily?

5357/tcp open wsdapi

On the Windows machine itself, ensure the "Network Discovery" rules are scoped correctly.

essential