PCIP Vulnerability Management 4 — Questions and Answers
Question 1: What is the maximum timeframe PCI DSS allows for deploying critical security patches to cardholder data environment systems?
- 7 days
- One month (Correct answer)
- 90 days
- There is no specified timeframe
Correct answer: One month
PCI DSS Requirement 6.3.3 requires critical patches to be installed within one month of release.
Question 2: Which tool type is specifically used to assess vulnerabilities in web applications under PCI DSS Requirement 6.4?
- Network vulnerability scanner
- Web application firewall only
- Web application vulnerability scanner or manual code review (Correct answer)
- Port scanner
Correct answer: Web application vulnerability scanner or manual code review
PCI DSS Requirement 6.4 requires web-facing applications to be reviewed via an automated web application vulnerability scanner or manual code review.
Question 3: In a penetration test for PCI DSS compliance, what does 'scoping' determine?
- The cost of the penetration test
- Which systems, networks, and applications are included in the test (Correct answer)
- The CVSS scores that will be accepted as passing
- The number of testers required
Correct answer: Which systems, networks, and applications are included in the test
Scoping defines the boundaries of the penetration test, identifying which in-scope systems, networks, and applications will be tested.
Question 4: A vulnerability scan identifies an open port on a CDE server that is not required for business operations. What is the appropriate PCI DSS response?
- Document the port as a known false positive
- Disable the service and close the port (Correct answer)
- Apply a CVSS score and re-scan in 90 days
- Report it to the card brands immediately
Correct answer: Disable the service and close the port
PCI DSS requires that only necessary services, protocols, and ports be enabled; unneeded ports must be disabled to reduce the attack surface.
Question 5: How does network segmentation impact the scope of vulnerability scanning under PCI DSS?
- Segmentation eliminates all scanning requirements
- Effective segmentation can reduce the number of systems that must be scanned as part of the CDE (Correct answer)
- Segmentation has no impact on vulnerability scanning scope
- Segmentation requires more frequent scanning of all systems
Correct answer: Effective segmentation can reduce the number of systems that must be scanned as part of the CDE
Proper network segmentation isolates the CDE, reducing the number of in-scope systems that require vulnerability scanning.
Question 6: What must an organization do if a vulnerability scan produces a 'false positive' result?
- Automatically apply patches for all false positives
- Document the false positive with evidence and submit an exception to the ASV for external scans (Correct answer)
- Report the false positive to PCI SSC directly
- Perform a penetration test to confirm all false positives
Correct answer: Document the false positive with evidence and submit an exception to the ASV for external scans
For external scans, false positives must be documented with supporting evidence and submitted to the ASV, who can confirm and exclude them from the failing findings.
Question 7: Which of the following is NOT a valid method for satisfying the PCI DSS web application security review requirement for public-facing applications?
- Installation of a web application firewall
- Manual code review by a qualified specialist
- Automated web application vulnerability scanning
- Network-layer penetration test only (Correct answer)
Correct answer: Network-layer penetration test only
A network-layer penetration test alone does not satisfy the web application security review requirement, which demands application-layer assessment via WAF, code review, or web app scanning.
What is the maximum timeframe PCI DSS allows for deploying critical security patches to cardholder data environment systems?