QUALYS VULNERABILITY
MANAGEMENT SELF PACED
TRAINING REVIEW 2026 VERIFIED
QUESTIONS WITH ACCURATE
ANSWERS
◉ 2. Sensitive authentication data should never be:
Answer: B)Stored
◉ 3. PCI Security Standards Council is made up of:
Answer: A)Major Credit Card Companies
◉ 4. The "stakeholder that is required to hold the Scan Customer
responsible for compliance is:
Answer: D)QSA
◉ 5. vulnerability scan report that was created using the PCI Scan
Report Template (in Qualys VM), will display each detected
vulnerability, along with its______________.
Answer: A)PASS/FAIL status
◉ 6. PCI DSS 11.2.1 (internal scanning) requires the resolution
of_________
vulnerabilities.
Answer: B)High-risk
, ◉ 7. When viewing vulnerability details from an external PCI scan, you
can view the following data (choose 3):
Answer: A)solution
B)results
D)threat
◉ 8. Which PCI DSS "Stakeholder" does Qualys represent?
Answer: A)Approved Scanning Vendor (ASV)
◉ 9. Which of the twelve (12) PCI DSS requirements are covered or
addressed by the Qualys PCI Compliance application? (choose 3)
Answer: A)6
C)1
D11
◉ 10. Automated "Fault Injection" testing can typically detect
___________of Web application vulnerabilities.
Answer: D)80 to 85%
◉ 11. Cardholder Data includes (choose 2):
Answer: A)Cardholder name
C)Primary Account number
MANAGEMENT SELF PACED
TRAINING REVIEW 2026 VERIFIED
QUESTIONS WITH ACCURATE
ANSWERS
◉ 2. Sensitive authentication data should never be:
Answer: B)Stored
◉ 3. PCI Security Standards Council is made up of:
Answer: A)Major Credit Card Companies
◉ 4. The "stakeholder that is required to hold the Scan Customer
responsible for compliance is:
Answer: D)QSA
◉ 5. vulnerability scan report that was created using the PCI Scan
Report Template (in Qualys VM), will display each detected
vulnerability, along with its______________.
Answer: A)PASS/FAIL status
◉ 6. PCI DSS 11.2.1 (internal scanning) requires the resolution
of_________
vulnerabilities.
Answer: B)High-risk
, ◉ 7. When viewing vulnerability details from an external PCI scan, you
can view the following data (choose 3):
Answer: A)solution
B)results
D)threat
◉ 8. Which PCI DSS "Stakeholder" does Qualys represent?
Answer: A)Approved Scanning Vendor (ASV)
◉ 9. Which of the twelve (12) PCI DSS requirements are covered or
addressed by the Qualys PCI Compliance application? (choose 3)
Answer: A)6
C)1
D11
◉ 10. Automated "Fault Injection" testing can typically detect
___________of Web application vulnerabilities.
Answer: D)80 to 85%
◉ 11. Cardholder Data includes (choose 2):
Answer: A)Cardholder name
C)Primary Account number