webApp.secure sits behind the Internet-facing perimeter defenses (firewalls, IDS/IPS, etc.) and in front of the Web environment (IIS, Apache, WebSphere®, etc.).
No, the Intended Use Guidelines are updated dynamically in real-time based on the content of the site. Changes to the website are automatically recognized.
The comprehensive application protection provided by webApp.secure LiveCD (as with the Professional Edition) satisfies PCI 6.6 compliance requirements. However, the limited logging capabilities may require additional development on the part of the user to be fully compliant.
Beware of "pretenders" that claim PCI 6 compliance, but do nothing more than rudimentary HTTP protocol inspection. These products have no ability to stop SQL injection, cross-site scripting, or other sophisticated application-manipulation attacks that concern the Payment Card Industry Security Standards Council (PCI Security Standards.org).
No, webApp.secure was designed from the ground up to be as easy to use as it is effective. Unique functionality makes it very intelligent and automatic, which dramatically reduces on-going administration costs/efforts.