PCI DSS penetration testing: what Requirement 11.4 demands, and the significant-change trap that catches teams between annual audits.