- | Page
ACAS Best Practice Knowledge Exam 1,2,3,4,5 and 6 Questions And Answers With Complete Solutions
Question 1: A vulnerability will be marked as mitigated in the
Tenable.sc repository if a subsequent scan determines that the vulnerability is no longer present on the endpoint.
- True
- False
CORRECT ANSWER : a) True
Question 2: Which of the following views is best for viewing IP
address details?
- Active Scan View
- Vulnerability Summary
- IP Summary
- Remediation Summary
CORRECT ANSWER : c) IP Summary
- | Page
Question 3: Nessus Agents are lightweight Nessus scanners
installed on the endpoint, according to the ACAS Agent Rapid Deployment Guide.
- True
- False
CORRECT ANSWER : a) True
Question 4: Per the Best Practices Guide, which of the following
statements are true?
- The TASKORD defines several target types on which Nessus
- Nessus Agents can be installed on additional endpoints above
- Per the TASKORD, organizations' endpoints which leverage
- If you use Nessus Agents, then you don't need any other
- All the above
Agents are required to be installed.
TASKORD requirement.
Nessus Agents must also be scanned with the Nessus active scanner using ACAS Best Practice Guide Agent Differential scan policy.
scanning tools for ACAS.
- | Page
CORRECT ANSWER : a) b) c)
Question 5: Nessus Agent and Manager use the same software.
- True
- False
CORRECT ANSWER : b) False
Question 6: Per the Best Practices Guide, which of these
statements is true?
- ACAS TASKORD 20-0020 FRAGO 3 clarifies that only
- DISA SCAP-compliant, automated benchmarks are still
- Audit files are proprietary formatted XML files that define
- Tenable distributes audit files via the Tenable.sc Feed that is
- None of the above
DISA STIG Tenable Audit files are to be used for configuration scanning in ACAS.
acceptable for ingest into CMRS.
how ACAS should check for configuration with a specified benchmark.
used to update Tenable.sc
- | Page
CORRECT ANSWER : a) c) d)
Question 7: It has been 20 days since your last configuration
(STIG) scan. Per FRAGO 2 of the Task Order 20-0020, which of the following statements reflects your current compliance status?
- In compliance because configuration scans are only required
- In compliance because vulnerability scans are only required
- Out of compliance because configuration scans are required
- Out of compliance because vulnerability scans are required
every 30 days.
every 21 days.
every 14 days.
every single day.
CORRECT ANSWER : a)
Question 8: Choose the Tenable.sc Severity Level that
corresponds to the Configuration result. Tenable re-used severity levels for configuration results.
- Critical - Not used with configuration