Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 105

Acme, Inc. is acquiring SeCloud, LLC, a small cloud security company. Before finalizing the acquisition, Acme wants to ensure SeCloud’s information systems are compliant with the Payment Card Industry Data Security Standard (PCI DSS). What type of assessment would provide the BEST level of assurance?
  • A A vulnerability assessment of SeCloud’s information system to identify non-compliance with PCI DSS-related controls.
  • B An internal security audit of all PCI DSS-related controls by teams from both companies to ensure full transparency.
  • C A security audit performed by a third party that provides a certified report.
  • D An external party security audit that provides a certified report.
Reveal correct answer

Correct answer: C

Explanation

OBJ. 6.5 - A third-party security audit provides an independent and certified assessment, ensuring the most reliable and unbiased verification of PCI DSS compliance. While internal audits or vulnerability assessments may uncover issues, they lack the independence and formal certification required for external assurance. For support or reporting issues, include Question ID: 67d9692c531aa8d1859b24ae in your ticket. Thank you.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need