How current must anti-malware solutions be kept?
- A.Update annually, given that the standard exempts virtual machines from the anti-malware requirements for SAQ C-VT merchants
- B.Update quarterly, which Requirement 6.3.3 requires within one month of release for patches that address critical vulnerabilities
- C.Anti-malware mechanisms must be kept current with the latest signatures, updates, and definitions through automatic updates
- D.Update only when new threats emerge, as internal scanning may be replaced by patch management reporting for SAQ D merchants
Why C is correct
Anti-malware solutions must receive automatic updates to maintain current signatures and definitions for detecting the latest threats.
Know someone studying for PCI DSS? Send them this one.