ACAS Best Practice Knowledge Examination - Version 3
Advanced Technical Assessment
Exam Title:
Assured Compliance Assessment Solution (ACAS) Best Practice Knowledge Examination: Advanced
Technical Mastery of Vulnerability Management Operations, Compliance Scanning Architecture,
Agent-Based Deployments, and Enterprise Risk Analysis for DoD Cybersecurity Professionals
EXAMINATION INSTRUCTIONS
This advanced examination consists of 150 multiple-choice questions covering the complete ACAS
Best Practice Guide, TASKORD 20-0020, and FRAGOs 1-3. The exam is designed for experienced
cybersecurity professionals managing enterprise ACAS deployments.
Time Allowed: 180 minutes
Passing Score: 75%
Reference Materials: ACAS Best Practices Guide, TASKORD 20-0020, FRAGOs 1-
3, Tenable.sc Documentation
SECTION 1: ACAS ARCHITECTURE AND INFRASTRUCTURE
Question 1
According to the ACAS Best Practices Guide, what is the maximum number of hosts that should be
targeted in a single active scan?
A) 500
B) 1,000
C) 2,500
D) 5,000
Correct Answer: C
Rationale: The ACAS Best Practices Guide specifies a maximum of 2,500 hosts for a single targeted scan
to maintain scan performance and prevent resource exhaustion. This limit ensures scans complete within
acceptable timeframes while maintaining data accuracy .
,Question 2
Which of the following statements about Tenable.sc repositories is correct regarding active scan
storage?
A) The Cumulative Repository stores only the most recent scan results
B) The Current Repository stores the most recent scan results while the Cumulative Repository
maintains vulnerability history
C) Both repositories store identical data
D) Repositories are only used for configuration compliance data
Correct Answer: B
Rationale: The Current Repository stores the most recent scan results, while the Cumulative Repository
maintains vulnerability history across multiple scans. Vulnerabilities in the Cumulative Repository include
those that have been recast, accepted, or mitigated and later found vulnerable on rescan .
Question 3
Per the TASKORD, which ACAS component must be deployed to VPN entry points for passive
monitoring?
A) Nessus Scanner
B) Tenable.sc
C) Nessus Network Monitor (NNM)
D) Nessus Manager
Correct Answer: C
Rationale: The Task Order requires deploying NNM to VPN entry points to enable passive monitoring of
VPN terrain and discovery of endpoints connecting via VPN. NNM data is similar to Nessus remote
checks, with findings based on protocol analysis being reliably accurate, while others based on
application banners may be less accurate .
Question 4
What is the primary purpose of deploying NNM internal to the AO on each circuit connecting AO
networks?
A) To replace active scanning entirely
B) To enable passive monitoring across network boundaries
C) To provide firewall protection
D) To manage user authentication
Correct Answer: B
Rationale: Per Task Order/FRAGO requirements, organizations must deploy at least one NNM internal to
the AO on each circuit that connects AO Unclassified and Classified networks to enable comprehensive
passive monitoring .
,Question 5
According to the ACAS Best Practices Guide, what is the minimum scan data retention requirement?
A) 30 days in Tenable.sc with additional data stored elsewhere for a total of at least 90 days
B) 90 days in Tenable.sc only
C) 180 days in Tenable.sc
D) 365 days in Tenable.sc only
Correct Answer: A
Rationale: While repositories can be configured to save active scan results for 30 days, this is only
sufficient if additional data is stored elsewhere for a total of at least 90 days. The default retention period
of 365 days may be required in some environments .
Question 6
Which Tenable.sc User Role has the permission to create scan zones, repositories, and organizations?
A) Security Manager
B) Administrator
C) Executive
D) Analyst
Correct Answer: B
Rationale: The Administrator role has the highest level of permissions in Tenable.sc, including the ability
to create scan zones, repositories, and organizations. Security Manager, Executive, and Analyst roles have
more limited permissions .
Question 7
What is the purpose of creating Scan Zones in Tenable.sc?
A) To organize users by geographic location
B) To associate IP addresses or ranges with one or more scanners for targeted scanning
C) To group vulnerabilities by severity
D) To manage plugin updates
Correct Answer: B
Rationale: Scan zones are areas of the network that you want to target in an active scan, associating IP
addresses or ranges with one or more scanners. You must create scan zones in order to run active scans
in Tenable Security Center .
Question 8
What is the CCRI inspection window duration according to the Best Practices Guide?
, A) 12-24 hours
B) 12-36 hours
C) 48-72 hours
D) 60 hours
Correct Answer: C
Rationale: Per the Best Practices Guide, organizations should provision Nessus scanners and Scan Zones
to ensure they can scan all their hosts during a CCRI visit, which currently lasts 48-72 hours .
Question 9
According to the Tenable ACAS whitepaper, what is a key benefit of the ACAS solution?
A) Complete Vision - The most comprehensive view of deployed assets and potential weaknesses
B) Limited visibility to reduce false positives
C) Restricted reporting capabilities
D) Local-only scanning without enterprise integration
Correct Answer: A
Rationale: According to the Tenable ACAS whitepaper, key benefits include Complete Vision (the most
comprehensive view of deployed assets and potential weaknesses), Situational Awareness, Fast
Communications, Risk Measurement, and Continuous Compliance .
Question 10
Which of the following components is RECOMMENDED but NOT provided by the ACAS baseline
according to Tenable?
A) Tenable.sc
B) Nessus Scanners
C) Tenable.ot
D) Nessus Agents
Correct Answer: C
Rationale: According to the Tenable ACAS whitepaper, Tenable.sc, Nessus scanners, Nessus Network
Monitor, and Nessus Agents are provided by ACAS. Tenable.ot is listed as "Recommended" but not
provided in the baseline ACAS offering .
Question 11
What is the purpose of Assurance Report Cards in Tenable.sc?
A) To grade users on their security awareness
B) To continuously measure the effectiveness of security policies based on strategic objectives
C) To provide financial assurance for security investments
D) To rank vendors by security capabilities
Advanced Technical Assessment
Exam Title:
Assured Compliance Assessment Solution (ACAS) Best Practice Knowledge Examination: Advanced
Technical Mastery of Vulnerability Management Operations, Compliance Scanning Architecture,
Agent-Based Deployments, and Enterprise Risk Analysis for DoD Cybersecurity Professionals
EXAMINATION INSTRUCTIONS
This advanced examination consists of 150 multiple-choice questions covering the complete ACAS
Best Practice Guide, TASKORD 20-0020, and FRAGOs 1-3. The exam is designed for experienced
cybersecurity professionals managing enterprise ACAS deployments.
Time Allowed: 180 minutes
Passing Score: 75%
Reference Materials: ACAS Best Practices Guide, TASKORD 20-0020, FRAGOs 1-
3, Tenable.sc Documentation
SECTION 1: ACAS ARCHITECTURE AND INFRASTRUCTURE
Question 1
According to the ACAS Best Practices Guide, what is the maximum number of hosts that should be
targeted in a single active scan?
A) 500
B) 1,000
C) 2,500
D) 5,000
Correct Answer: C
Rationale: The ACAS Best Practices Guide specifies a maximum of 2,500 hosts for a single targeted scan
to maintain scan performance and prevent resource exhaustion. This limit ensures scans complete within
acceptable timeframes while maintaining data accuracy .
,Question 2
Which of the following statements about Tenable.sc repositories is correct regarding active scan
storage?
A) The Cumulative Repository stores only the most recent scan results
B) The Current Repository stores the most recent scan results while the Cumulative Repository
maintains vulnerability history
C) Both repositories store identical data
D) Repositories are only used for configuration compliance data
Correct Answer: B
Rationale: The Current Repository stores the most recent scan results, while the Cumulative Repository
maintains vulnerability history across multiple scans. Vulnerabilities in the Cumulative Repository include
those that have been recast, accepted, or mitigated and later found vulnerable on rescan .
Question 3
Per the TASKORD, which ACAS component must be deployed to VPN entry points for passive
monitoring?
A) Nessus Scanner
B) Tenable.sc
C) Nessus Network Monitor (NNM)
D) Nessus Manager
Correct Answer: C
Rationale: The Task Order requires deploying NNM to VPN entry points to enable passive monitoring of
VPN terrain and discovery of endpoints connecting via VPN. NNM data is similar to Nessus remote
checks, with findings based on protocol analysis being reliably accurate, while others based on
application banners may be less accurate .
Question 4
What is the primary purpose of deploying NNM internal to the AO on each circuit connecting AO
networks?
A) To replace active scanning entirely
B) To enable passive monitoring across network boundaries
C) To provide firewall protection
D) To manage user authentication
Correct Answer: B
Rationale: Per Task Order/FRAGO requirements, organizations must deploy at least one NNM internal to
the AO on each circuit that connects AO Unclassified and Classified networks to enable comprehensive
passive monitoring .
,Question 5
According to the ACAS Best Practices Guide, what is the minimum scan data retention requirement?
A) 30 days in Tenable.sc with additional data stored elsewhere for a total of at least 90 days
B) 90 days in Tenable.sc only
C) 180 days in Tenable.sc
D) 365 days in Tenable.sc only
Correct Answer: A
Rationale: While repositories can be configured to save active scan results for 30 days, this is only
sufficient if additional data is stored elsewhere for a total of at least 90 days. The default retention period
of 365 days may be required in some environments .
Question 6
Which Tenable.sc User Role has the permission to create scan zones, repositories, and organizations?
A) Security Manager
B) Administrator
C) Executive
D) Analyst
Correct Answer: B
Rationale: The Administrator role has the highest level of permissions in Tenable.sc, including the ability
to create scan zones, repositories, and organizations. Security Manager, Executive, and Analyst roles have
more limited permissions .
Question 7
What is the purpose of creating Scan Zones in Tenable.sc?
A) To organize users by geographic location
B) To associate IP addresses or ranges with one or more scanners for targeted scanning
C) To group vulnerabilities by severity
D) To manage plugin updates
Correct Answer: B
Rationale: Scan zones are areas of the network that you want to target in an active scan, associating IP
addresses or ranges with one or more scanners. You must create scan zones in order to run active scans
in Tenable Security Center .
Question 8
What is the CCRI inspection window duration according to the Best Practices Guide?
, A) 12-24 hours
B) 12-36 hours
C) 48-72 hours
D) 60 hours
Correct Answer: C
Rationale: Per the Best Practices Guide, organizations should provision Nessus scanners and Scan Zones
to ensure they can scan all their hosts during a CCRI visit, which currently lasts 48-72 hours .
Question 9
According to the Tenable ACAS whitepaper, what is a key benefit of the ACAS solution?
A) Complete Vision - The most comprehensive view of deployed assets and potential weaknesses
B) Limited visibility to reduce false positives
C) Restricted reporting capabilities
D) Local-only scanning without enterprise integration
Correct Answer: A
Rationale: According to the Tenable ACAS whitepaper, key benefits include Complete Vision (the most
comprehensive view of deployed assets and potential weaknesses), Situational Awareness, Fast
Communications, Risk Measurement, and Continuous Compliance .
Question 10
Which of the following components is RECOMMENDED but NOT provided by the ACAS baseline
according to Tenable?
A) Tenable.sc
B) Nessus Scanners
C) Tenable.ot
D) Nessus Agents
Correct Answer: C
Rationale: According to the Tenable ACAS whitepaper, Tenable.sc, Nessus scanners, Nessus Network
Monitor, and Nessus Agents are provided by ACAS. Tenable.ot is listed as "Recommended" but not
provided in the baseline ACAS offering .
Question 11
What is the purpose of Assurance Report Cards in Tenable.sc?
A) To grade users on their security awareness
B) To continuously measure the effectiveness of security policies based on strategic objectives
C) To provide financial assurance for security investments
D) To rank vendors by security capabilities