After changes, vulnerability scans can be performed by which of the following?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

After changes, vulnerability scans can be performed by which of the following?

Explanation:
After changes, you can have vulnerability scans performed by either an Approved Scanning Vendor (ASV) or by qualified internal resources. This reflects PCI DSS rules that external vulnerability scans must be done by an ASV, while internal vulnerability scans must be conducted by qualified personnel after significant changes (and at least quarterly). The flexibility lets you choose the path that fits your environment and resources, as long as the scans are performed by someone who is properly qualified and the processes follow the standard.

After changes, you can have vulnerability scans performed by either an Approved Scanning Vendor (ASV) or by qualified internal resources. This reflects PCI DSS rules that external vulnerability scans must be done by an ASV, while internal vulnerability scans must be conducted by qualified personnel after significant changes (and at least quarterly). The flexibility lets you choose the path that fits your environment and resources, as long as the scans are performed by someone who is properly qualified and the processes follow the standard.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy