Which of the following is true regarding internal vulnerability scans?
A.
They must be performed after a significant change
B.
They must be performed by an Approved Scanning Vendor (ASV)
C.
They must be performed by QSA personnel
D.
They must be performed at least annually
The Answer Is:
A
This question includes an explanation.
Explanation:
According to the PCI DSS v3.2.1 Quick Reference Guide1, internal vulnerability scans must be performed after a significant change in any component or configuration that affects cardholder data or payment processing systems. This is one of the requirements for identifying and mitigating vulnerabilities that could compromise cardholder data.
Assessor_New_V4 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"