What is ACAS? - ANS -ACAS is a network-based security compliance and assessment
capability
designed to provide awareness of the security posture and network health of
DoD networks.
Which of the following best describes the SecurityCenter? - ANS -The central console that
provides continuous asset-based security and
compliance monitoring
A vulnerability is a weakness or an attack that can compromise your system. - ANS -False
(a vulnerability does not include an attack)
The Nessus scanner monitors data at rest, while the PVS monitors data in motion. - ANS -
True
PVS detects vulnerabilities based on network traffic instead of actively scanning hosts. -
ANS -True
Which ACAS component performs active vulnerability and compliance scanning? - ANS -
Nessus
CMRS is a tool to provide DoD component- and enterprise-level situational awareness by
quantitatively displaying an organization's security posture. - ANS -True
Select the Task Order for the Implementation of Assured Compliance Assessment Solution
1
(ACAS) for the Enterprise: - ANS -13-670
Page
, Which page loads by default when you log in to SecurityCenter? Select the best answer. -
ANS -Dashboard
Which of the following pages show the date and time of the most recent plugin updates? -
ANS -Plugins, Feeds
Which page allows you to set your local time zone? - ANS -Profile
What is an organization? - ANS -A group of individuals who are responsible for a set of
common assets
What is a scan zone? - ANS -A defined static range of IP addresses with an associated
Nessus scanner(s)
What is the maximum size of a SecurityCenter 5 Repository? - ANS -32 GB
The IP address(es) you are scanning must be contained in both the definition of the scan zone
and the definition of the repository. - ANS -True
What SecurityCenter role is responsible for setting up scan zones? - ANS -Administrator
How can you get your SecurityCenter plugin updates? - ANS -Automatically, from DISA's
plugin server, Manually from the DoD Patch Repository
The SecurityCenter Plugins menu displays a list of script files used by Nessus and PVS scanners
2
to collect and interpret vulnerability, compliance, and configuration data. - ANS -True
Page