For systems not commonly affected by malware, which action aligns with best practice regarding anti-virus applicability?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

For systems not commonly affected by malware, which action aligns with best practice regarding anti-virus applicability?

Explanation:
Not every system needs anti-virus—the level of protection should match the system’s actual exposure to malware. If a system is not commonly targeted and is well protected by strong perimeter defenses and network segmentation, the risk reduction can be achieved without installing anti-virus. In this scenario, relying on those perimetral controls to block and limit threats is considered best practice, avoiding unnecessary overhead and maintenance from antivirus software on that specific system. If threat patterns or system exposure change, you would reassess, but under the given conditions the preventive emphasis on perimeter defenses aligns with prudent risk management.

Not every system needs anti-virus—the level of protection should match the system’s actual exposure to malware. If a system is not commonly targeted and is well protected by strong perimeter defenses and network segmentation, the risk reduction can be achieved without installing anti-virus. In this scenario, relying on those perimetral controls to block and limit threats is considered best practice, avoiding unnecessary overhead and maintenance from antivirus software on that specific system. If threat patterns or system exposure change, you would reassess, but under the given conditions the preventive emphasis on perimeter defenses aligns with prudent risk management.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy