Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 105
Acme, Inc. is acquiring SeCloud, LLC, a small cloud security company. Before finalizing the acquisition, Acme wants to ensure SeCloud’s information systems are compliant with the Payment Card Industry Data Security Standard (PCI DSS). What type of assessment would provide the BEST level of assurance?
- A A vulnerability assessment of SeCloud’s information system to identify non-compliance with PCI DSS-related controls.
- B An internal security audit of all PCI DSS-related controls by teams from both companies to ensure full transparency.
- C A security audit performed by a third party that provides a certified report.
- D An external party security audit that provides a certified report.
Reveal correct answer
Correct answer: C
Explanation
OBJ. 6.5 - A third-party security audit provides an independent and certified assessment, ensuring the most reliable and unbiased verification of PCI DSS compliance. While internal audits or vulnerability assessments may uncover issues, they lack the independence and formal certification required for external assurance. For support or reporting issues, include Question ID: 67d9692c531aa8d1859b24ae in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
