Which of the following is true regarding internal vulnerability scans?

Which of the following is true regarding internal vulnerability scans?
A . They must be performed after a significant change.
B . They must be performed by an Approved Scanning Vendor (ASV).
C . They must be performed by QSA personnel.
D . They must be performed at least annually.

Answer: A

Explanation:

Comprehensive Detailed Step by Step Explanation with All PCI DSS and Qualified Security Assessor V4 References

Relevant PCI DSS Requirement: Internal vulnerability scans are discussed under PCI DSS Requirement

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments