Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A company is required to comply with PCI DSS. What is the primary purpose of conducting quarterly network vulnerability scans?

⚠ Common exam trap

CAS-005 often tests the confusion between vulnerability scanning and other security assessments like firewall audits or encryption validation, leading candidates to select a secondary benefit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To detect and remediate vulnerabilities in a timely manner

The primary purpose of quarterly network vulnerability scans under PCI DSS is to detect and remediate vulnerabilities in a timely manner. PCI DSS Requirement 11.2 mandates quarterly internal and external vulnerability scans to identify security weaknesses and address them before they can be exploited. This proactive approach helps maintain a secure network environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To ensure firewall rules are correctly configured

    Why it's wrong here

    Quarterly scans detect known vulnerabilities on in-scope hosts; firewall rule correctness is verified through configuration reviews and penetration testing, not scan output. It tempts because scans do reveal exposed ports, and rule auditing is a valid PCI activity, just not the scans' primary purpose.

  • ✗

    To verify encryption strength

    Why it's wrong here

    Scans detect unpatched software and misconfigurations; encryption strength is validated through cryptographic configuration review, not vulnerability scanning signatures. It tempts because scans can flag weak protocols such as SSL, yet confirming cipher suites and key lengths requires dedicated assessment rather than quarterly ASV scans.

  • ✓

    To detect and remediate vulnerabilities in a timely manner

    Why this is correct

    Quarterly scanning satisfies PCI DSS Requirement 11.3.2 by identifying exploitable weaknesses in external and internal networks before attackers do, enabling remediation within the mandated timeframe. Continuous detection keeps the cardholder data environment compliant between annual penetration tests, directly addressing the standard's timely-remediation constraint.

  • ✗

    To monitor user access logs

    Why it's wrong here

    Scans identify vulnerabilities in systems and applications; user access logs are reviewed through log monitoring and file integrity processes under PCI DSS Requirement 10. It tempts because scan reports include timestamps and host details resembling audit trails, but they capture no authentication or authorisation events.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.