Mandatory access control decides what a program is allowed to do regardless of the permissions of the user running it. On Ubuntu and Debian that means AppArmor, which is installed and running on most servers and, on a great many of them, confining almost nothing.
This page shows every loaded profile with its mode, the processes running confined, and the processes running with no profile at all. The mode is the part to check first. A profile in complain mode logs what it would have blocked and blocks nothing — useful while you tune a new profile, worthless as protection if it was left that way and forgotten. Enforce is what actually constrains a process.
The list of unconfined processes is the more interesting half. Anything reachable from the network belongs under a profile: the web server, the database, the mail daemon, and any application server you have written yourself. Recent denials are shown too, since a service that suddenly misbehaves after a profile change usually explains itself there.