Which of the following is NOT an example of a component listed in the ASV Scan Report?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

Which of the following is NOT an example of a component listed in the ASV Scan Report?

Explanation:
ASV Scan Reports are built around clearly identifying the assets that were scanned and linking each finding to that asset. The information you expect to see includes how the asset is identified (IP address, and if resolvable, its FQDN) and a unique reference or vector used to track the scan results for that asset. Subnet mask describes the size of a network address block and isn’t a detail about a specific asset or its vulnerabilities, so it isn’t a data point you’d find in a standard ASV Scan Report. That’s why subnet mask is the element that doesn’t fit among the report components.

ASV Scan Reports are built around clearly identifying the assets that were scanned and linking each finding to that asset. The information you expect to see includes how the asset is identified (IP address, and if resolvable, its FQDN) and a unique reference or vector used to track the scan results for that asset. Subnet mask describes the size of a network address block and isn’t a detail about a specific asset or its vulnerabilities, so it isn’t a data point you’d find in a standard ASV Scan Report. That’s why subnet mask is the element that doesn’t fit among the report components.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy