CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS). The report must demonstrate that the organization regularly scans for vulnerabilities and remediates them within specified timeframes. Which of the following log snippets would be MOST relevant to include as evidence for this requirement?

  1. A2023-10-25 09:30:00 SCANNER [Tenable.io] Scan ID 12345 completed. Found 15 critical, 30 high vulnerabilities.
  2. B2023-10-26 14:05:12 INFO User 'jsmith' logged into the HR portal from 192.168.1.50.
  3. C2023-10-23 16:00:00 APP_LOG Order #56789 processed successfully for customer 'Jane Doe'.
  4. D2023-10-24 11:15:00 FIREWALL Blocked connection attempt from 203.0.113.10 to port 22 on server 'DB01'.
Show answer & explanation

Correct answer: A. 2023-10-25 09:30:00 SCANNER [Tenable.io] Scan ID 12345 completed. Found 15 critical, 30 high vulnerabilities.

PCI DSS requires regular vulnerability scanning. The log snippet from 'Tenable.io' explicitly indicates a completed vulnerability scan and its findings, directly serving as evidence of compliance with the scanning requirement.

Why the other options are wrong

  • B. This log shows user activity, which is not directly related to vulnerability scanning or remediation.
  • C. This log indicates application activity, which is irrelevant to vulnerability scanning and remediation.
  • D. This log shows firewall activity, which is a security control but not direct evidence of vulnerability scanning.

PCI DSS Compliance Evidence

Documentation and logs that demonstrate an organization's adherence to the Payment Card Industry Data Security Standard requirements, particularly for vulnerability management.

  • Requires regular vulnerability scanning (external and internal).
  • Mandates timely remediation of identified vulnerabilities.
  • Evidence includes scan reports, remediation tickets, and policy documents.

Memory trick: PCI needs proof of scans, not just daily logs.

More Reporting and Communication questions