After a significant change, which is required regarding scans?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

After a significant change, which is required regarding scans?

Explanation:
After a significant change, vulnerability scans must cover both the internal and external environments, and any needed rescans should be performed by qualified personnel. Running internal scans checks for weaknesses inside the network that outsiders can’t reach directly, while external scans look at the perimeter to find issues that could be exploited from outside. Re-scanning as needed ensures that fixes have been properly applied and that the change didn’t introduce new vulnerabilities. This comprehensive approach is necessary because relying on only one type of scan or skipping rescans could miss gaps or newly created risks.

After a significant change, vulnerability scans must cover both the internal and external environments, and any needed rescans should be performed by qualified personnel. Running internal scans checks for weaknesses inside the network that outsiders can’t reach directly, while external scans look at the perimeter to find issues that could be exploited from outside. Re-scanning as needed ensures that fixes have been properly applied and that the change didn’t introduce new vulnerabilities. This comprehensive approach is necessary because relying on only one type of scan or skipping rescans could miss gaps or newly created risks.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy