ACAS Best Practice Knowledge Examination - Version 2
Comprehensive 150-Question Practice Exam
Exam Title:
Assured Compliance Assessment Solution (ACAS) Best Practice Knowledge Examination: Advanced
Technical Assessment of Vulnerability Scanning Operations, Compliance Verification, and Enterprise
Security Management Across All Six Knowledge Domains
EXAMINATION INSTRUCTIONS
This examination consists of 150 multiple-choice questions covering ACAS Best Practice Guide
requirements and associated Task Orders (TASKORD 20-0020 and FRAGOs 1-3). The exam covers all six
knowledge domains (Exams 1-6) and is intended for cybersecurity professionals responsible for
implementing, managing, and maintaining ACAS within Department of Defense environments.
Time Allowed: 180 minutes
Passing Score: 75%
Reference Materials: ACAS Best Practices Guide, TASKORD 20-0020, FRAGOs 1-
3, Tenable.sc Documentation
SECTION 1: ACAS FUNDAMENTALS AND ARCHITECTURE (Questions
1-25)
Question 1
Which of the following ACAS components is responsible for distributing custom DISA scan policies and
audit files?
A) Nessus Scanner
B) Nessus Manager
C) Patch Repository
D) Tenable.sc
Correct Answer: C
Rationale: The Patch Repository in ACAS distributes custom DISA scan policies, audit files, and other
configuration files required for DoD-specific scanning. It is not used for operating system
,patches. Tenable.sc manages data, Nessus Scanner performs active scanning, and Nessus Manager
coordinates operations .
Question 2
A vulnerability will be marked as mitigated in the Tenable.sc repository if a subsequent scan
determines that the vulnerability is no longer present on the endpoint.
A) True
B) False
Correct Answer: A
Rationale: According to ACAS best practices, vulnerabilities are automatically marked as mitigated in
the Tenable.sc repository when a subsequent scan confirms the vulnerability is no longer present on the
endpoint. This automated process ensures accurate vulnerability status tracking .
Question 3
Which analysis tool in Tenable.sc sorts vulnerabilities by plugin ID count and displays columns of
Plugin ID, Total, and Severity?
A) Vulnerability Summary
B) IP Summary
C) Remediation Summary
D) IAVM Summary
Correct Answer: B
Rationale: The IP Summary sorts vulnerabilities by plugin ID count with columns of plugin ID, Total, and
Severity that can be sorted by clicking on column headers. Vulnerability Summary lists addresses, scores,
and counts; Remediation Summary provides prioritized actions; IAVM Summary displays DoD IAVA/IAVB
mappings .
Question 4
Per the ACAS Best Practices Guide, which of the following statements about Nessus Agents is true?
A) Nessus Agent and Nessus Manager use the same software
B) Nessus Agents are lightweight Nessus scanners installed on the endpoint
C) Nessus Agents replace the need for active scanning
D) Nessus Agents cannot perform compliance scanning
Correct Answer: B
Rationale: Nessus Agents are lightweight Nessus scanners installed on the endpoint, according to the
ACAS Agent Rapid Deployment Guide. They use different software than Nessus Manager (A), do not
replace active scanning (C), and can perform compliance scanning (D) .
,Question 5
According to the ACAS Best Practices Guide, how many import repositories can you select for a single
scan?
A) Only one
B) A maximum of three
C) You can select all your available repositories
D) As many as you like, if none of them are agent repositories
Correct Answer: A
Rationale: The ACAS Best Practice Guide specifies that a single scan can only be configured with one
import repository. This limitation ensures data consistency and prevents potential conflicts when
vulnerability findings are stored across multiple repositories .
Question 6
Networks using Dynamic Host Configuration Protocol (DHCP) require which active scan setting to be
enabled to properly track hosts?
A) Rollover Option
B) Enable Safe Checks
C) Track hosts which have been issued new IP addresses
D) Remove vulnerabilities from scanned hosts that have been inactive for X days
Correct Answer: C
Rationale: Networks using DHCP require the "Track hosts which have been issued new IP addresses"
setting to properly track hosts across scans. Without this setting, hosts receiving new IP addresses could
be incorrectly identified as new hosts, leading to duplicate vulnerability records .
Question 7
What is the purpose of the "Rollover Option" in Nessus scan configuration?
A) To automatically reschedule scans that fail
B) To allow the next scan to use a different repository
C) To specify the behavior when the target IP space changes
D) To enable continuous scanning after initial completion
Correct Answer: C
Rationale: The Rollover Option addresses how scans should handle changes in target IP space. It is
specifically important for networks using DHCP to ensure all hosts are scanned even if IP assignments
change .
Question 8
, Per the ACAS Best Practices Guide, which Tenable.sc resources are proprietary formatted XML files that
define how ACAS should check for configuration with a specified STIG?
A) Credentials
B) Queries
C) Policies
D) Audit Files
Correct Answer: D
Rationale: Audit Files are proprietary formatted XML files that define how ACAS should check for
configuration with a specified STIG benchmark. Credentials are authentication information; Queries are
used for analysis; Policies define general scan parameters .
Question 9
What is the recommended maximum number of target hosts per Nessus scan in ACAS?
A) 500
B) 1000
C) 5000
D) 10000
Correct Answer: C
Rationale: According to ACAS best practices, scans should not exceed 5000 targets per scan to maintain
performance and accuracy. Larger scans should be broken into multiple scan jobs .
Question 10
Which of the custom DISA scan policies on the Patch Repository has most or all the plugin families
enabled?
A) OS Discovery
B) Vulnerability
C) Configuration
D) Differential
Correct Answer: B
Rationale: The "Vulnerability" scan policy (custom DISA policy) is the recommended policy for
credentialed vulnerability scanning. It has most or all plugin families enabled to provide comprehensive
vulnerability detection .
Question 11
According to the Best Practices Guide, what must be done before accepting risk for a vulnerability?
Comprehensive 150-Question Practice Exam
Exam Title:
Assured Compliance Assessment Solution (ACAS) Best Practice Knowledge Examination: Advanced
Technical Assessment of Vulnerability Scanning Operations, Compliance Verification, and Enterprise
Security Management Across All Six Knowledge Domains
EXAMINATION INSTRUCTIONS
This examination consists of 150 multiple-choice questions covering ACAS Best Practice Guide
requirements and associated Task Orders (TASKORD 20-0020 and FRAGOs 1-3). The exam covers all six
knowledge domains (Exams 1-6) and is intended for cybersecurity professionals responsible for
implementing, managing, and maintaining ACAS within Department of Defense environments.
Time Allowed: 180 minutes
Passing Score: 75%
Reference Materials: ACAS Best Practices Guide, TASKORD 20-0020, FRAGOs 1-
3, Tenable.sc Documentation
SECTION 1: ACAS FUNDAMENTALS AND ARCHITECTURE (Questions
1-25)
Question 1
Which of the following ACAS components is responsible for distributing custom DISA scan policies and
audit files?
A) Nessus Scanner
B) Nessus Manager
C) Patch Repository
D) Tenable.sc
Correct Answer: C
Rationale: The Patch Repository in ACAS distributes custom DISA scan policies, audit files, and other
configuration files required for DoD-specific scanning. It is not used for operating system
,patches. Tenable.sc manages data, Nessus Scanner performs active scanning, and Nessus Manager
coordinates operations .
Question 2
A vulnerability will be marked as mitigated in the Tenable.sc repository if a subsequent scan
determines that the vulnerability is no longer present on the endpoint.
A) True
B) False
Correct Answer: A
Rationale: According to ACAS best practices, vulnerabilities are automatically marked as mitigated in
the Tenable.sc repository when a subsequent scan confirms the vulnerability is no longer present on the
endpoint. This automated process ensures accurate vulnerability status tracking .
Question 3
Which analysis tool in Tenable.sc sorts vulnerabilities by plugin ID count and displays columns of
Plugin ID, Total, and Severity?
A) Vulnerability Summary
B) IP Summary
C) Remediation Summary
D) IAVM Summary
Correct Answer: B
Rationale: The IP Summary sorts vulnerabilities by plugin ID count with columns of plugin ID, Total, and
Severity that can be sorted by clicking on column headers. Vulnerability Summary lists addresses, scores,
and counts; Remediation Summary provides prioritized actions; IAVM Summary displays DoD IAVA/IAVB
mappings .
Question 4
Per the ACAS Best Practices Guide, which of the following statements about Nessus Agents is true?
A) Nessus Agent and Nessus Manager use the same software
B) Nessus Agents are lightweight Nessus scanners installed on the endpoint
C) Nessus Agents replace the need for active scanning
D) Nessus Agents cannot perform compliance scanning
Correct Answer: B
Rationale: Nessus Agents are lightweight Nessus scanners installed on the endpoint, according to the
ACAS Agent Rapid Deployment Guide. They use different software than Nessus Manager (A), do not
replace active scanning (C), and can perform compliance scanning (D) .
,Question 5
According to the ACAS Best Practices Guide, how many import repositories can you select for a single
scan?
A) Only one
B) A maximum of three
C) You can select all your available repositories
D) As many as you like, if none of them are agent repositories
Correct Answer: A
Rationale: The ACAS Best Practice Guide specifies that a single scan can only be configured with one
import repository. This limitation ensures data consistency and prevents potential conflicts when
vulnerability findings are stored across multiple repositories .
Question 6
Networks using Dynamic Host Configuration Protocol (DHCP) require which active scan setting to be
enabled to properly track hosts?
A) Rollover Option
B) Enable Safe Checks
C) Track hosts which have been issued new IP addresses
D) Remove vulnerabilities from scanned hosts that have been inactive for X days
Correct Answer: C
Rationale: Networks using DHCP require the "Track hosts which have been issued new IP addresses"
setting to properly track hosts across scans. Without this setting, hosts receiving new IP addresses could
be incorrectly identified as new hosts, leading to duplicate vulnerability records .
Question 7
What is the purpose of the "Rollover Option" in Nessus scan configuration?
A) To automatically reschedule scans that fail
B) To allow the next scan to use a different repository
C) To specify the behavior when the target IP space changes
D) To enable continuous scanning after initial completion
Correct Answer: C
Rationale: The Rollover Option addresses how scans should handle changes in target IP space. It is
specifically important for networks using DHCP to ensure all hosts are scanned even if IP assignments
change .
Question 8
, Per the ACAS Best Practices Guide, which Tenable.sc resources are proprietary formatted XML files that
define how ACAS should check for configuration with a specified STIG?
A) Credentials
B) Queries
C) Policies
D) Audit Files
Correct Answer: D
Rationale: Audit Files are proprietary formatted XML files that define how ACAS should check for
configuration with a specified STIG benchmark. Credentials are authentication information; Queries are
used for analysis; Policies define general scan parameters .
Question 9
What is the recommended maximum number of target hosts per Nessus scan in ACAS?
A) 500
B) 1000
C) 5000
D) 10000
Correct Answer: C
Rationale: According to ACAS best practices, scans should not exceed 5000 targets per scan to maintain
performance and accuracy. Larger scans should be broken into multiple scan jobs .
Question 10
Which of the custom DISA scan policies on the Patch Repository has most or all the plugin families
enabled?
A) OS Discovery
B) Vulnerability
C) Configuration
D) Differential
Correct Answer: B
Rationale: The "Vulnerability" scan policy (custom DISA policy) is the recommended policy for
credentialed vulnerability scanning. It has most or all plugin families enabled to provide comprehensive
vulnerability detection .
Question 11
According to the Best Practices Guide, what must be done before accepting risk for a vulnerability?