nerdexam
EC-Council

312-50V11 · Question #8

When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?

The correct answer is B. At least once a year and after any significant upgrade or modification. PCI-DSS Requirement 11.3 mandates that organizations conduct penetration testing at least once per year and after any significant infrastructure upgrade or modification.

Information Security and Ethical Hacking Fundamentals

Question

When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?

Options

  • AAt least twice a year or after any significant upgrade or modification
  • BAt least once a year and after any significant upgrade or modification
  • CAt least once every two years and after any significant upgrade or modification
  • DAt least once every three years or after any significant upgrade or modification

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    86% (18)
  • D
    10% (2)

Why each option

PCI-DSS Requirement 11.3 mandates that organizations conduct penetration testing at least once per year and after any significant infrastructure upgrade or modification.

AAt least twice a year or after any significant upgrade or modification

PCI-DSS does not require penetration testing twice a year as a baseline; the requirement is annually, not semi-annually.

BAt least once a year and after any significant upgrade or modificationCorrect

PCI-DSS Requirement 11.3 explicitly states that penetration testing must be performed at least annually and after any significant changes to the network or applications, such as a new system component installation, network topology changes, or firewall rule modifications. The 'and' conjunction is critical - both conditions are required rather than either/or. This ensures ongoing validation of security controls over time and after change events.

CAt least once every two years and after any significant upgrade or modification

A two-year cycle does not meet the PCI-DSS annual minimum penetration testing requirement defined in Requirement 11.3.

DAt least once every three years or after any significant upgrade or modification

A three-year cycle significantly under-meets the PCI-DSS requirement and would place an organization out of compliance.

Concept tested: PCI-DSS penetration testing frequency requirements

Source: https://www.pcisecuritystandards.org/documents/Penetration_Testing_Guidance_March_2015.pdf

Topics

#PCI-DSS#penetration testing#compliance#security standards

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice