After identifying high-risk vulnerabilities in an internal scan, what action is required?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

After identifying high-risk vulnerabilities in an internal scan, what action is required?

Explanation:
After identifying high-risk vulnerabilities, the priority is to remediate them and then verify the fixes with rescans. The key is that the rescans must be performed by qualified personnel to ensure the results are accurate, properly validated, and well-documented for compliance purposes. Simply addressing the issues without verification leaves risk lingering, while stopping after management notification doesn’t resolve the vulnerabilities. So, the best action is to address vulnerabilities and perform rescans to verify resolution, with rescans conducted by qualified personnel.

After identifying high-risk vulnerabilities, the priority is to remediate them and then verify the fixes with rescans. The key is that the rescans must be performed by qualified personnel to ensure the results are accurate, properly validated, and well-documented for compliance purposes. Simply addressing the issues without verification leaves risk lingering, while stopping after management notification doesn’t resolve the vulnerabilities. So, the best action is to address vulnerabilities and perform rescans to verify resolution, with rescans conducted by qualified personnel.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy