ISC2 Governance, Risk and Compliance (CGRC) Practice Question
You are designing a continuous-monitoring schedule for a cloud-hosted e-commerce platform that must comply with PCI-DSS v4.0. Assuming no significant changes occur in the environment, which activity is still explicitly required at least once every three months to stay compliant?
Rotate the cryptographic keys used to encrypt stored cardholder data.
Conduct penetration testing to verify network-segmentation controls.
Review and update the formal risk assessment for the cardholder data environment.
Perform internal and external vulnerability scans of all in-scope systems.
PCI-DSS v4.0 Requirement 11.3.1 and 11.3.2 mandate that both internal vulnerability scans and external scans performed by an Approved Scanning Vendor (ASV) occur at least quarterly, even when no significant changes have taken place.
Key rotation for stored cardholder data is governed by Requirement 3.6 and is typically tied to cryptoperiod or key-compromise events, not a set three-month interval. Segmentation penetration tests (Requirement 11.4.5) are required at least annually and after any changes to segmentation controls, not quarterly. The formal risk assessment (Requirement 12.2) must be completed at least annually or whenever the environment changes significantly, so it is not a quarterly obligation. Therefore, conducting internal and external vulnerability scans is the only task among the options that PCI-DSS specifically requires every quarter.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI-DSS v4.0 and why is it important?
Open an interactive chat with Bash
What are internal vulnerability scans and how do they differ from external scans?
Open an interactive chat with Bash
What role does an ASV play in external vulnerability scans?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .