Well, if you do not use anything that requires those ports, e.g., most NFS versions require rpcbind and spiceproxy is required for the SPICE (QXL) based VM/CT and Host console, then it can be just fine to firewall them off or disable the respective systemd services.