During the most recent 12 months, how many internal vulnerability scans must be performed?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

During the most recent 12 months, how many internal vulnerability scans must be performed?

Explanation:
Internal vulnerability scans must be performed at least quarterly. That means four scans in any 12-month period to regularly check the cardholder data environment for new or evolving weaknesses and to remediate them promptly. The minimum remains four per year, even if no changes occur. You would only have more than four if there were significant changes or you chose to run additional scans for extra assurance. So, for the most recent 12 months, the minimum number required is four, making four the correct answer. Three is not enough to meet the quarterly requirement, while five or six would indicate more than the minimum due to extra scans, not the base rule.

Internal vulnerability scans must be performed at least quarterly. That means four scans in any 12-month period to regularly check the cardholder data environment for new or evolving weaknesses and to remediate them promptly. The minimum remains four per year, even if no changes occur. You would only have more than four if there were significant changes or you chose to run additional scans for extra assurance. So, for the most recent 12 months, the minimum number required is four, making four the correct answer. Three is not enough to meet the quarterly requirement, while five or six would indicate more than the minimum due to extra scans, not the base rule.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy