PCIP Vulnerability Management 5 β Questions and Answers
Question 1: What is the role of threat intelligence in a PCI DSS-aligned vulnerability management program?
- It replaces the need for vulnerability scanning
- It provides context about active exploits to help prioritize remediation (Correct answer)
- It is only relevant for Level 1 merchants
- It is used exclusively for penetration testing
Correct answer: It provides context about active exploits to help prioritize remediation
Threat intelligence identifies which vulnerabilities are being actively exploited, helping organizations prioritize remediation of the most dangerous flaws first.
Question 2: Under PCI DSS, what happens to the ASV scan requirement if a merchant acquires a new external IP address range mid-quarter?
- The new range is excluded until the next scheduled quarterly scan
- The new range must be included in an out-of-cycle scan before it processes card data (Correct answer)
- The merchant must notify PCI SSC before adding IP ranges
- No action is needed until the next annual assessment
Correct answer: The new range must be included in an out-of-cycle scan before it processes card data
Any new external-facing infrastructure that enters the CDE scope must be scanned before it can be used to process card data, regardless of quarterly scheduling.
Question 3: Which of the following describes a penetration test methodology that is consistent with PCI DSS Requirement 11.4?
- Automated-only scanning with no manual exploitation attempts
- Industry-accepted approach covering network and application layers with exploitation attempts (Correct answer)
- Scanning limited to the external network perimeter only
- Annual review of firewall rules only
Correct answer: Industry-accepted approach covering network and application layers with exploitation attempts
PCI DSS requires penetration tests to follow an industry-accepted methodology covering both network and application layers with actual exploitation attempts.
Question 4: A penetration tester successfully pivots from a non-CDE system into the cardholder data environment. What does this finding indicate about the organization's controls?
- Network segmentation controls are effective
- Segmentation controls have failed and must be reviewed and remediated (Correct answer)
- The finding is acceptable if patched within 30 days
- Only the ASV needs to be notified
Correct answer: Segmentation controls have failed and must be reviewed and remediated
A successful pivot into the CDE demonstrates that network segmentation has failed, requiring immediate remediation to restore isolation of cardholder data.
Question 5: What is the minimum frequency for penetration testing of the CDE per PCI DSS Requirement 11.4?
- Every six months
- Annually and after significant infrastructure or application changes (Correct answer)
- Quarterly, same as vulnerability scanning
- Every two years for Level 2 merchants
Correct answer: Annually and after significant infrastructure or application changes
PCI DSS requires penetration testing at least annually and after any significant changes to the CDE network or applications.
Question 6: How should vulnerability management findings be communicated to management under a PCI DSS-compliant program?
- Only technical staff need to review vulnerability findings
- Findings must be reported to executive management with risk rankings and remediation timelines (Correct answer)
- Findings are only shared with the QSA during assessments
- Automated scan reports are sufficient without management summaries
Correct answer: Findings must be reported to executive management with risk rankings and remediation timelines
PCI DSS expects that vulnerability findings, including risk rankings and remediation status, are communicated to appropriate management to ensure accountability.
Question 7: Which of the following scenarios requires an immediate out-of-cycle vulnerability scan under PCI DSS?
- A new employee joins the IT security team
- A new firewall rule is added to the corporate (non-CDE) network
- A new server is added to the cardholder data environment (Correct answer)
- A QSA requests additional documentation
Correct answer: A new server is added to the cardholder data environment
Adding a new server to the CDE constitutes a significant infrastructure change, triggering a requirement for an internal vulnerability scan after the change.
What is the role of threat intelligence in a PCI DSS-aligned vulnerability management program?