Question 1
Which mitigation technique is commonly used to defend against cross-site scripting (XSS)?
Correct Answer:
Input validation and output encoding
Explanation:
Cross-site scripting is prevented by controlling untrusted input and how it’s rendered in a browser. The most effective and commonly used defense is to validate inputs to reject dangerous content and to encode data on output so anything potentially harmful is treated as text rather than executable code. Input validation reduces the amount of unsafe data that can enter the system, while output encoding neutralizes data when it’s displayed by transforming characters like <, >, &, and quotes into safe HTML entities. The right encoding depends on the context—HTML content needs HTML entity encoding, URLs need URL encoding, and data injected into scripts or attributes requires context-appropriate escaping. Together with broader safeguards like content security policies and proper data sanitization, this approach provides solid protection against XSS. Relying on client-side scripting alone isn’t enough because security controls must be enforced on the server and validated by the browser; storing passwords in plaintext has nothing to do with preventing XSS and creates other serious risks; disabling JavaScript on clients is impractical and would break legitimate functionality while not reliably stopping XSS.
Question 2
Which of the following vulnerabilities would cause an automatic failure?
Correct Answer:
Default or built-in accounts with default passwords
Explanation:
Automatic failure happens when a vulnerability reveals a baseline security control failure that is universally unacceptable. Default or built-in accounts with default passwords are such a case because those credentials are widely known and easily exploited across many systems. PCI DSS requires disabling or changing default accounts and using unique, strong passwords, so having defaults present means the environment is immediately insecure and fails the assessment regardless of other issues. The other vulnerabilities are serious and require fixes, but they depend on context and remediation steps; they aren’t universally disqualifying in the same automatic way as default credentials.
Question 3
Which statement accurately describes SSL usage on host devices in PCI scanning?
Correct Answer:
Any form of SSL on a host device is an automatic failure, with the exception for POS devices that can prove no downgrade vulnerability.
Explanation:
SSL on host devices is treated as a red flag in PCI scanning because cardholder data must be protected with strong cryptography and legacy protocols like SSL are not considered acceptable for protecting data in transit. When a host device uses SSL, it often signals the presence of weak or deprecated encryption (or a potential downgrade path), which ASV scans flag as a failure. The only exception is POS devices, which may be allowed to use SSL if they can prove there is no downgrade vulnerability—meaning they won’t expose data through weaker protocols or older TLS versions. In short, strong, up-to-date encryption is required across the environment, and SSL usage on host devices is not permitted unless a POS device can demonstrate it isn’t vulnerable to downgrades.
Question 4
In the Overall Scan Results, what information is not included?
Correct Answer:
IP addresses
Explanation:
In an Overall Scan Results view, you get a quick, high-level snapshot of the scan: whether the scan passed or failed, when the current scan results expire (so you know when to rescan for compliance), and how many components were included in the assessment. The specific IP addresses of the scanned hosts aren’t shown in this summary; you’d see those details in the per-host or detailed results if you need them. This keeps the overview focused on outcome, timing, and scope, which is what you need to gauge compliance quickly. So, the information not included in the Overall Scan Results is the IP addresses.
Question 5
Insecure direct object references and directory traversal are examples of which vulnerability category?
Correct Answer:
Improper access control
Explanation:
These examples show a failure to enforce proper authorization for accessing resources. Insecure direct object references occur when an app exposes direct references to internal objects (like IDs) and doesn’t verify that the requester is allowed to access that object; changing the reference can reveal or modify data the user shouldn’t see. Directory traversal likewise lets an attacker manipulate file paths to reach restricted files outside the intended directory, bypassing access checks. Both highlight weaknesses in controlling who can access what, which is the essence of improper access control. The other options describe different issues: cross-site scripting involves injecting scripts into pages, CSRF tricks a user into performing unintended actions, and broken authentication concerns weaknesses in login or session management.
Question 1
Exam overview

About this Exam

Prepare with the PCI Approved Scanning Vendor (ASV) Online Practice Test practice quiz. This question bank includes 10 questions covering devices, insecure, vulnerability, data, and protection. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

PCI Approved Scanning Vendor (ASV) Online Practice Test

This practice set contains 10 questions from the matching question bank and focuses on devices, insecure, vulnerability, data, and protection. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions