nerdexam
EC-Council

312-50V9 · Question #169

When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?

The correct answer is A. At least once a year and after any significant upgrade or modification. PCI DSS Requirement 11.3 explicitly mandates external and internal penetration testing at least once per year and after any significant infrastructure or application upgrade or modification.

Introduction to Ethical Hacking

Question

When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?

Options

  • AAt least once a year and after any significant upgrade or modification
  • BAt least once every three years or after any significant upgrade or modification
  • CAt least twice a year or after any significant upgrade or modification
  • DAt least once every two years and after any significant upgrade or modification

How the community answered

(24 responses)
  • A
    88% (21)
  • C
    4% (1)
  • D
    8% (2)

Why each option

PCI DSS Requirement 11.3 explicitly mandates external and internal penetration testing at least once per year and after any significant infrastructure or application upgrade or modification.

AAt least once a year and after any significant upgrade or modificationCorrect

PCI DSS Requirement 11.3 states that organizations must implement a penetration testing methodology and conduct penetration tests at least annually and after any significant infrastructure or application changes. This annual cadence ensures that new vulnerabilities introduced over time or via changes are identified before attackers can exploit them. The 'after significant change' clause ensures that newly deployed systems or modified architectures do not introduce untested attack surfaces.

BAt least once every three years or after any significant upgrade or modification

A three-year interval is not aligned with PCI DSS requirements and would leave too large a window for undetected vulnerabilities to persist.

CAt least twice a year or after any significant upgrade or modification

Twice per year exceeds the minimum PCI DSS mandate, which is at least once annually, not twice - this option misrepresents the standard's actual requirement.

DAt least once every two years and after any significant upgrade or modification

A two-year interval does not meet the PCI DSS annual minimum penetration testing requirement specified in Requirement 11.3.

Concept tested: PCI DSS penetration testing frequency requirements

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#penetration testing frequency#compliance requirements#security testing

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice