312-50V9 · Question #169
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
The correct answer is A. At least once a year and after any significant upgrade or modification. PCI DSS Requirement 11.3 explicitly mandates external and internal penetration testing at least once per year and after any significant infrastructure or application upgrade or modification.
Question
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
Options
- AAt least once a year and after any significant upgrade or modification
- BAt least once every three years or after any significant upgrade or modification
- CAt least twice a year or after any significant upgrade or modification
- DAt least once every two years and after any significant upgrade or modification
How the community answered
(24 responses)- A88% (21)
- C4% (1)
- D8% (2)
Why each option
PCI DSS Requirement 11.3 explicitly mandates external and internal penetration testing at least once per year and after any significant infrastructure or application upgrade or modification.
PCI DSS Requirement 11.3 states that organizations must implement a penetration testing methodology and conduct penetration tests at least annually and after any significant infrastructure or application changes. This annual cadence ensures that new vulnerabilities introduced over time or via changes are identified before attackers can exploit them. The 'after significant change' clause ensures that newly deployed systems or modified architectures do not introduce untested attack surfaces.
A three-year interval is not aligned with PCI DSS requirements and would leave too large a window for undetected vulnerabilities to persist.
Twice per year exceeds the minimum PCI DSS mandate, which is at least once annually, not twice - this option misrepresents the standard's actual requirement.
A two-year interval does not meet the PCI DSS annual minimum penetration testing requirement specified in Requirement 11.3.
Concept tested: PCI DSS penetration testing frequency requirements
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.