PCI Vulnerability Management & Testing — Questions and Answers
Question 1: What is a penetration test and how often does PCI DSS require it?
- A simulated cyber attack to identify vulnerabilities, required at least annually and after significant changes (Correct answer)
- A test measuring network cable durability
- An employee aptitude test for IT positions
- A test required only when a breach has occurred
Correct answer: A simulated cyber attack to identify vulnerabilities, required at least annually and after significant changes
PCI DSS requires penetration testing at least annually and after any significant infrastructure or application change to identify exploitable vulnerabilities before real attackers find them.
Question 2: What is vulnerability scanning in PCI compliance?
- Automated scanning of systems to identify known security weaknesses, required quarterly by an Approved Scanning Vendor (Correct answer)
- Scanning physical documents for confidential information
- Checking employees' vulnerability to phishing emails only
- A one-time scan performed during initial PCI certification
Correct answer: Automated scanning of systems to identify known security weaknesses, required quarterly by an Approved Scanning Vendor
Quarterly external vulnerability scans by an ASV and internal vulnerability scans (also quarterly at minimum) identify known weaknesses in systems, enabling remediation before exploitation.
Question 3: What is the role of an Approved Scanning Vendor (ASV)?
- A PCI Council-approved organization that conducts external vulnerability scans for merchants (Correct answer)
- A vendor approved to sell scanning equipment
- A government-approved security firm
- Any IT company can perform ASV scans without approval
Correct answer: A PCI Council-approved organization that conducts external vulnerability scans for merchants
ASVs are organizations validated by the PCI SSC to perform external vulnerability scanning services using PCI-approved scanning solutions and procedures.
Question 4: What is patch management in PCI compliance?
- The process of applying software updates to fix security vulnerabilities in a timely manner (Correct answer)
- Managing physical patches on network cables
- A sewing technique for repairing server room carpeting
- Only updating antivirus software definitions
Correct answer: The process of applying software updates to fix security vulnerabilities in a timely manner
PCI DSS requires installing critical security patches within one month of release and establishing a process for identifying and prioritizing all relevant patches for systems in the cardholder data environment.
Question 5: What is a Qualified Security Assessor (QSA)?
- A PCI Council-certified professional authorized to conduct on-site PCI DSS compliance assessments (Correct answer)
- Any security professional with IT experience
- A government security inspector
- An insurance company risk assessor
Correct answer: A PCI Council-certified professional authorized to conduct on-site PCI DSS compliance assessments
QSAs are individuals certified by the PCI SSC who have demonstrated expertise in information security and PCI DSS requirements, authorized to perform official compliance assessments.
Question 6: What is the purpose of file integrity monitoring (FIM) in PCI compliance?
- To detect unauthorized changes to critical system files that could indicate a security breach (Correct answer)
- To monitor file storage capacity on servers
- To track employee file access for productivity
- To manage document version control
Correct answer: To detect unauthorized changes to critical system files that could indicate a security breach
FIM tools detect changes to critical system files, configuration files, and content files, alerting security teams to unauthorized modifications that could indicate a compromise.
What is a penetration test and how often does PCI DSS require it?