CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS) Requirement 11.2, which mandates regular vulnerability scanning. The analyst needs to present evidence that all in-scope systems are scanned quarterly by an internal scanner and annually by an Approved Scanning Vendor (ASV). Which of the following metrics would BEST demonstrate compliance with this requirement?

  1. APercentage of in-scope systems scanned quarterly by internal tools and annually by ASV
  2. BNumber of vulnerabilities identified per scan
  3. CTotal number of security incidents related to cardholder data
  4. DTime taken to remediate critical vulnerabilities
Show answer & explanation

Correct answer: A. Percentage of in-scope systems scanned quarterly by internal tools and annually by ASV

PCI DSS Requirement 11.2 specifically mandates the frequency and type of scanning for all in-scope systems. The percentage of in-scope systems scanned quarterly by internal tools and annually by ASV directly demonstrates adherence to these explicit requirements.

Why the other options are wrong

  • B. This metric measures findings, not the coverage or frequency of scanning as required by 11.2.
  • C. This measures incident response, not compliance with vulnerability scanning requirements.
  • D. This measures remediation efficiency, not compliance with scanning frequency and coverage mandates.

PCI DSS 11.2 Compliance Metric

A metric used to demonstrate adherence to PCI DSS Requirement 11.2, which specifies regular internal and external vulnerability scanning for all systems in the cardholder data environment.

  • Mandates quarterly internal vulnerability scans.
  • Requires annual external vulnerability scans conducted by an Approved Scanning Vendor (ASV).
  • Focuses on coverage and frequency of scanning for in-scope systems.

Memory trick: PCI scans cover all cards every quarter and year.

More Reporting and Communication questions