1/18
EUNICE
ACAS Training and Best Practice Reviews WITH 100% SURE
ANSWERS
A vulnerability will be marked as mitigated in the Tenable.sc repository if a subsequent scan determines that the vulnerability is no longer present on the endpoint.
Select the correct answer.
- True
- False
a Select the best answer.
- Active Scan View
- Vulnerability Summary
- IP Summary
- Remediation Summary
c Nessus Agents are lightweight Nessus scanners installed on the endpoint, according to the ACAS Agent Rapid Deployment Guide.
Select the best answer.
- True
- False
a 1 / 3
2/18
Per the Best Practices Guide, which of the following statements are true?Select the correct answer(s).
- The TASKORD defines several target
- Nessus Agents can be installed on
- Per the TASKORD organizations
- If you use Nessus Agents, then you don't
- All the above
types on which Nessus Agents are required to be installed.
addition endpoints above TASKORD requirement.
endpoints which leverage a Nessus Agents must also be scanned with the Nessus active scanner using ACAS Best Practice Guide Agent Differential scan policy.
need any other scanning tools for ACAS.
a b c Nessus Agent and Manager use the same software.
Select the correct answer.
- True
- False
b Per the Best Practices Guide, which of these statements is true.
Select the correct answers.
- ACAS TASKORD 20-0020 FRAGO 3
- DISA SCAP-compliant, automated
- Audit files are proprietary formatted XML
- Tenable distributes audit files via the the
- None of the above
clarifies that only DISA STIG Tenable Audit files are to be used for configuration scanning in ACAS.
benchmarks are still acceptable for ingest into CMRS.
files that define how ACAS should check for configuration with a specified benchmark.
Tenable.sc Feed that is used to update Tenable.sc
a c d 2 / 3
3/18
It has been 20 days since your last configuration (STIG) scan. Per FRAGO 2 of the Task Order 20-0020, which of the following statements reflects your current compliance status?
Select the best answer.
In compliance because configuration scans are only required every 30 days.In compliance because vulnerability scans are only required every 21 days.Out of compliance because configuration scans are required every 14 days.Out of compliance because vulnerability scans are required every single day.a Choose the Tenable.sc Severity Level that corresponds to the Configuration result.Tenable re-used severity levels for configuration results.
- Critical
- High
- Medium
- Info
- Not used with configuration
- Failed configuration check
- Unable to Determine/Error
- Passed configuration check
Per the ACAS Best Practices Guide, which of the following Tenable.sc resources are proprietary formatted XML files that define how ACAS should check for configuration with a specified STIG?
Select the best answer:
- Credentials
- Queries
- Policies
- Audit Files
d The Tenable Nessus vulnerability scanner allows you to perform compliance audits of numerous platforms including (but not limited to) databases, Cisco, Unix, and Windows configurations as well as sensitive data discovery based on regex contained in audit files.
Audit files are XML-based text files that contain the specific configuration, file permission, and access control tests to be performed.
Log in to Tenable Security Center via the user interface.Click Scans > Audit Files.The Audit Files page appears.
Scan zone Scan zones are areas of your network that you want to target in an active scan
Associates an IP address or range of IP addresses with one or more scanners
You must create scan zones in order to run active scans in Tenable Security Center.
- / 3