After a significant network change, which statement is true about scanning?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

After a significant network change, which statement is true about scanning?

Explanation:
After significant network changes, vulnerability scanning must cover both internal and external surfaces and be carried out by qualified personnel. This ensures any new weaknesses introduced by the changes are detected before they can be exploited. External scanning must be performed by an Approved Scanning Vendor (ASV), while internal scanning should be conducted by individuals with the appropriate qualifications and expertise. This combination keeps both external exposure and internal network risk in check after changes. Choosing options that say scans are optional, only internal scans, or that rescans aren’t needed misses the requirement to verify security after changes and to confirm remediation, which is why those do not fit.

After significant network changes, vulnerability scanning must cover both internal and external surfaces and be carried out by qualified personnel. This ensures any new weaknesses introduced by the changes are detected before they can be exploited. External scanning must be performed by an Approved Scanning Vendor (ASV), while internal scanning should be conducted by individuals with the appropriate qualifications and expertise. This combination keeps both external exposure and internal network risk in check after changes.

Choosing options that say scans are optional, only internal scans, or that rescans aren’t needed misses the requirement to verify security after changes and to confirm remediation, which is why those do not fit.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy