PCIP Vulnerability Management 3 — Questions and Answers
Question 1: Which of the following is a key characteristic of a zero-day vulnerability in PCI DSS contexts?
- A vulnerability with a CVSS score of zero
- A flaw exploited before a vendor patch is available (Correct answer)
- A vulnerability discovered exactly on patch Tuesday
- A flaw that only affects point-of-sale terminals
Correct answer: A flaw exploited before a vendor patch is available
A zero-day vulnerability is one that is being exploited in the wild before the vendor has released a patch to address it.
Question 2: According to PCI DSS, who is qualified to perform internal vulnerability scans?
- Only QSA-certified individuals
- Only ASV-approved personnel
- Qualified internal staff or qualified third parties (internal scans do not require ASV) (Correct answer)
- The card brands must approve the internal scanning team
Correct answer: Qualified internal staff or qualified third parties (internal scans do not require ASV)
Internal vulnerability scans do not need to be performed by an ASV; they can be done by qualified internal personnel or qualified third parties.
Question 3: A company's web application firewall (WAF) is being used as a compensating control for a vulnerability in a web-facing application. What must the WAF compensating control include?
- Logging of all network traffic regardless of application layer
- Active monitoring and a defined rule set blocking exploitation of the specific vulnerability (Correct answer)
- Integration with the ASV scanning tool
- Approval from the acquiring bank only
Correct answer: Active monitoring and a defined rule set blocking exploitation of the specific vulnerability
A WAF used as a compensating control must be actively monitored and configured with rules that specifically prevent exploitation of the unpatched vulnerability.
Question 4: What is the significance of CVE (Common Vulnerabilities and Exposures) identifiers in PCI DSS vulnerability management?
- CVEs are used to assign CVSS scores to vulnerabilities
- CVEs provide a standardized reference for publicly known vulnerabilities, aiding in consistent tracking (Correct answer)
- CVEs replace the need for internal vulnerability scanning
- CVEs are only relevant to network-layer vulnerabilities
Correct answer: CVEs provide a standardized reference for publicly known vulnerabilities, aiding in consistent tracking
CVE identifiers provide a standardized naming convention for publicly known vulnerabilities, enabling consistent communication and tracking across organizations and tools.
Question 5: Under PCI DSS Requirement 11, after a significant infrastructure change, when must an internal vulnerability scan be performed?
- Within 90 days of the change
- After the next scheduled quarterly scan
- After the change is implemented (Correct answer)
- Only if the QSA requests it
Correct answer: After the change is implemented
PCI DSS requires internal vulnerability scans to be performed after any significant changes to the network or system components.
Question 6: Which of the following best describes the relationship between patch management and vulnerability management in PCI DSS?
- They are identical processes with the same requirements
- Patch management is a subset of vulnerability management, addressing remediation through software updates (Correct answer)
- Vulnerability management is only required when patch management fails
- Patch management is only for operating systems, while vulnerability management covers applications
Correct answer: Patch management is a subset of vulnerability management, addressing remediation through software updates
Patch management is a component of the broader vulnerability management program, focusing specifically on applying vendor-released fixes to address identified vulnerabilities.
Question 7: An organization running cardholder data environment systems on a shared hosting provider—who is responsible for ensuring vulnerability scans meet PCI DSS requirements?
- The hosting provider bears full responsibility
- The merchant retains compliance responsibility but may rely on the provider's scans if documented (Correct answer)
- Responsibility is split 50/50 between merchant and provider automatically
- The card brands assume responsibility for shared hosting environments
Correct answer: The merchant retains compliance responsibility but may rely on the provider's scans if documented
Merchants retain PCI DSS compliance responsibility even in shared hosting environments and must ensure scans meet requirements, whether performed by them or documented from the provider.
Which of the following is a key characteristic of a zero-day vulnerability in PCI DSS contexts?