After changes, vulnerability scans can be performed by which of the following?

Prepare for the PCI ASV Test with our in-depth quizzes. Study with realistic scenarios and multiple choice questions equipped with hints and explanations. Ace your certification with confidence!

Multiple Choice

After changes, vulnerability scans can be performed by which of the following?

Explanation:
After changes, you can have vulnerability scans performed by either an Approved Scanning Vendor (ASV) or by qualified internal resources. This reflects PCI DSS rules that external vulnerability scans must be done by an ASV, while internal vulnerability scans must be conducted by qualified personnel after significant changes (and at least quarterly). The flexibility lets you choose the path that fits your environment and resources, as long as the scans are performed by someone who is properly qualified and the processes follow the standard.

After changes, you can have vulnerability scans performed by either an Approved Scanning Vendor (ASV) or by qualified internal resources. This reflects PCI DSS rules that external vulnerability scans must be done by an ASV, while internal vulnerability scans must be conducted by qualified personnel after significant changes (and at least quarterly). The flexibility lets you choose the path that fits your environment and resources, as long as the scans are performed by someone who is properly qualified and the processes follow the standard.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy