What is a vulnerability scan?
- A.A manual code review, since the standard allows the entity to set its own definition of a significant change
- B.A penetration test, which Requirement 11.4 requires at least annually and after any significant change, exercising both the network layer and the application layer from inside and outside the network
- C.A network speed test, as software development lifecycle documentation was removed from Requirement 6 in v4.0
- D.An automated process that examines systems for known vulnerabilities, misconfigurations, and missing patches
Why D is correct
Vulnerability scanning uses automated tools to identify known vulnerabilities, misconfigurations, and missing patches across systems and applications.
Know someone studying for PCI DSS? Send them this one.