ISC2 Certified in Cybersecurity (CC)Security OperationsHard

A national retail chain is expanding its online presence and now accepts credit card payments directly through its website. To comply with PCI DSS (Payment Card Industry Data Security Standard) requirements, they must regularly test their systems by attempting to exploit vulnerabilities to determine if security controls are effective and to identify any potential entry points for attackers. Which security operation is mandated by PCI DSS for this purpose?

  1. ASecurity Assessments
  2. BSecurity Audits
  3. CVulnerability Scanning
  4. DPenetration Testing
Show answer & explanation

Correct answer: D. Penetration Testing

While vulnerability scanning identifies known weaknesses, penetration testing goes further by actively attempting to exploit those weaknesses (or discover new ones) to simulate a real-world attack. PCI DSS Requirement 11.3 specifically mandates penetration testing to evaluate the effectiveness of security controls and identify exploitable vulnerabilities, which aligns with the scenario's need to 'exploit vulnerabilities to determine if security controls are effective'.

Why the other options are wrong

  • A. Security assessments are broader, while penetration testing is a specific, active testing method.
  • B. Security audits review compliance with policies, not active exploitation of vulnerabilities.
  • C. Vulnerability scanning identifies weaknesses but doesn't actively exploit them to test controls.

Penetration Testing

A simulated cyber attack against an information system, network, or web application to check for exploitable vulnerabilities.

  • Actively attempts to exploit vulnerabilities.
  • Goes beyond vulnerability scanning.
  • Evaluates the effectiveness of security controls.

Memory trick: Pen Test Probes Potential Pathways.

More Security Operations questions