Which frequency is required for external vulnerability scans?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

Which frequency is required for external vulnerability scans?

Explanation:
External vulnerability scans must be done at least every quarter by an Approved Scanning Vendor. This quarterly cadence ensures that publicly exposed systems are regularly checked for newly discovered vulnerabilities, keeping the assessment current without requiring monthly scans. Performing scans more often than quarterly isn’t the standard minimum, while semiannual or annual frequencies would leave longer gaps where vulnerabilities could go undetected. Additionally, after any significant change to the network, a re-scan is required to verify that new changes haven’t introduced unaddressed weaknesses.

External vulnerability scans must be done at least every quarter by an Approved Scanning Vendor. This quarterly cadence ensures that publicly exposed systems are regularly checked for newly discovered vulnerabilities, keeping the assessment current without requiring monthly scans. Performing scans more often than quarterly isn’t the standard minimum, while semiannual or annual frequencies would leave longer gaps where vulnerabilities could go undetected. Additionally, after any significant change to the network, a re-scan is required to verify that new changes haven’t introduced unaddressed weaknesses.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy