SSCP Risk Identification, Monitoring, and Analysis Practice Question
A company is preparing for a PCI DSS assessment. According to PCI DSS requirements, how frequently must internal vulnerability scans be performed?
⚠ Common exam trap
Test-takers frequently confuse the quarterly internal scan requirement with the weekly external scan requirement (for internet-facing systems), leading them to incorrectly select 'Weekly' as the answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quarterly
PCI DSS Requirement 11.2.1 mandates that internal vulnerability scans must be performed at least quarterly and after any significant change in the network. This frequency ensures that new vulnerabilities introduced since the last scan are identified and remediated before they can be exploited. Quarterly scans are a minimum; more frequent scanning is recommended for high-risk environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Annually
Why it's wrong here
PCI DSS requires quarterly, not annually.
- ✗
Monthly
Why it's wrong here
PCI DSS requires internal vulnerability scans quarterly, not monthly; monthly exceeds the minimum and is not the specified cadence. Monthly scanning is tempting because it satisfies the quarterly requirement while adding margin, and would be a valid internal policy choice, but the question asks for the mandated frequency.
- ✗
Weekly
Why it's wrong here
PCI DSS requires internal vulnerability scans at least quarterly, with rescans after significant changes, so weekly exceeds the mandated minimum. It is tempting because weekly scanning is a common hardening practise, but the standard's stated frequency for internal scans is quarterly.
- ✓
Quarterly
Why this is correct
PCI DSS mandates that internal vulnerability scans be run at least quarterly, satisfying the assessment's recurring scanning obligation. Scans must also be repeated after any significant network change, but the baseline cadence the question asks for is quarterly.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.