nerdexam
EC-Council

312-50V11 · Question #392

Which of the following tools would be the best choice for achieving compliance with PCI Requirement 11?

The correct answer is C. Nessus. PCI DSS Requirement 11 mandates regular vulnerability scanning and penetration testing of network systems, and Nessus is an industry-standard tool built precisely for this purpose.

Vulnerability Analysis

Question

Which of the following tools would be the best choice for achieving compliance with PCI Requirement 11?

Options

  • ATruecrypt
  • BSub7
  • CNessus
  • DClamwin

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    79% (15)
  • D
    11% (2)

Why each option

PCI DSS Requirement 11 mandates regular vulnerability scanning and penetration testing of network systems, and Nessus is an industry-standard tool built precisely for this purpose.

ATruecrypt

TrueCrypt is a disk encryption utility relevant to PCI Requirement 3 (protect stored cardholder data), not Requirement 11, which focuses on active vulnerability scanning and penetration testing.

BSub7

Sub7 is a Remote Access Trojan used as malicious attack software and has no legitimate role in any PCI DSS compliance requirement.

CNessusCorrect

Nessus by Tenable is a widely used vulnerability scanner that performs the internal and external network scans required by PCI DSS Requirement 11.2, which calls for quarterly vulnerability assessments. The PCI Security Standards Council recognizes approved scanning vendors (ASVs) and Nessus is widely used in that capacity to identify missing patches, misconfigurations, and known CVEs. Its direct alignment with automated vulnerability discovery makes it the best tool match for satisfying Requirement 11 compliance.

DClamwin

ClamWin is an open-source antivirus tool relevant to PCI Requirement 5 (protect all systems against malware), not Requirement 11, which specifically mandates vulnerability scanning and security testing.

Concept tested: PCI DSS Requirement 11 vulnerability scanning compliance tools

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#Nessus#vulnerability scanning#compliance tools

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice