nerdexam
GAQM

CPEH-001 · Question #8

When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?

The correct answer is B. At least once a year and after any significant upgrade or modification. See the full explanation below for the reasoning.

Question

When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?

Options

  • AAt least twice a year or after any significant upgrade or modification
  • BAt least once a year and after any significant upgrade or modification
  • CAt least once every two years and after any significant upgrade or modification
  • DAt least once every three years or after any significant upgrade or modification

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    70% (19)
  • C
    4% (1)
  • D
    15% (4)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice