PCIP Vulnerability Management 2 — Questions and Answers
Question 1: Under PCI DSS, how frequently must internal vulnerability scans be performed?
- Once per year
- At least quarterly (Correct answer)
- Monthly
- After every system change only
Correct answer: At least quarterly
PCI DSS Requirement 11.3.1 requires internal vulnerability scans to be performed at least quarterly.
Question 2: Which CVSS score range is generally classified as 'Critical' severity?
- 4.0–6.9
- 7.0–8.9
- 9.0–10.0 (Correct answer)
- 5.0–7.4
Correct answer: 9.0–10.0
CVSS scores of 9.0–10.0 are classified as Critical, representing the highest severity vulnerabilities.
Question 3: A merchant discovers a vulnerability that has a patch available but cannot immediately apply it due to operational constraints. What is the PCI DSS-compliant response?
- Ignore the vulnerability until the next scheduled maintenance window
- Implement compensating controls and document the risk (Correct answer)
- Remove the affected system from the network permanently
- Submit a SAQ indicating the vulnerability is acceptable
Correct answer: Implement compensating controls and document the risk
When patching is delayed, merchants must implement compensating controls and document the associated risk per PCI DSS guidelines.
Question 4: What is the primary purpose of a vulnerability scan compared to a penetration test?
- Vulnerability scans exploit weaknesses; penetration tests only identify them
- Vulnerability scans identify potential weaknesses; penetration tests actively attempt to exploit them (Correct answer)
- They serve identical purposes but differ only in cost
- Penetration tests are automated; vulnerability scans are manual
Correct answer: Vulnerability scans identify potential weaknesses; penetration tests actively attempt to exploit them
Vulnerability scans detect and report potential security weaknesses, while penetration tests actively attempt to exploit those weaknesses to assess real impact.
Question 5: Which PCI DSS requirement mandates that new vulnerabilities be identified and addressed within one month of discovery for high-risk vulnerabilities?
- Requirement 6.3 (Correct answer)
- Requirement 11.3
- Requirement 12.2
- Requirement 8.6
Correct answer: Requirement 6.3
PCI DSS Requirement 6.3 covers security vulnerability management, including addressing high-risk vulnerabilities within one month.
Question 6: When an Approved Scanning Vendor (ASV) external scan returns a failing result, what must occur before the quarterly scan requirement is considered met?
- The entity must switch to a different ASV
- Vulnerabilities must be remediated and a passing rescan completed (Correct answer)
- A compensating control worksheet must be submitted to the card brand
- The QSA must sign off on the failing report
Correct answer: Vulnerabilities must be remediated and a passing rescan completed
A failing ASV scan requires remediation of identified vulnerabilities followed by a successful rescan to satisfy the quarterly external scan requirement.
Question 7: In the context of PCI DSS vulnerability management, what does 'risk ranking' of vulnerabilities help an organization achieve?
- It determines which vulnerabilities to ignore permanently
- It prioritizes remediation efforts based on potential impact and exploitability (Correct answer)
- It replaces the need for vulnerability scanning
- It satisfies the penetration testing requirement
Correct answer: It prioritizes remediation efforts based on potential impact and exploitability
Risk ranking allows organizations to prioritize which vulnerabilities to remediate first based on factors like severity, exploitability, and potential business impact.
Under PCI DSS, how frequently must internal vulnerability scans be performed?