ACAS Best Practice Knowledge Exam
Comprehensive 150-Question Practice Exam
Exam Title:
Assured Compliance Assessment Solution (ACAS) Best Practice Knowledge Examination:
Comprehensive Assessment of Vulnerability Management, Configuration Scanning, and Compliance
Framework Implementation for DoD Cybersecurity Professionals
EXAMINATION INSTRUCTIONS
This examination consists of 150 multiple-choice questions designed to assess comprehensive
knowledge of the ACAS Best Practice Guide and associated Task Orders (TASKORD 20-0020 and
FRAGOs). The exam covers all six knowledge domains (Exams 1-6) and is intended for cybersecurity
professionals responsible for implementing, managing, and maintaining ACAS within Department of
Defense environments.
Time Allowed: 180 minutes
Passing Score: 75%
Reference Materials: ACAS Best Practices Guide, TASKORD 20-0020, FRAGOs 1-
3, Tenable.sc Documentation
SECTION 1: ACAS FUNDAMENTALS AND ARCHITECTURE (Questions
1-25)
Question 1
What is the primary purpose of the Assured Compliance Assessment Solution (ACAS) within the
Department of Defense?
A) To replace all existing network monitoring tools with a single unified platform
B) To provide automated vulnerability assessment and configuration compliance scanning for DoD
networks
C) To manage user authentication and access control across all DoD systems
D) To serve as a replacement for traditional antivirus software
,Correct Answer: B
Rationale: ACAS is the DoD's enterprise solution for automated vulnerability assessment and
configuration compliance scanning. It is designed to identify security weaknesses, verify compliance with
security policies, and provide risk-based prioritization for remediation efforts. Options A, C, and D
describe functions not associated with ACAS's core mission.
Question 2
Which of the following components is NOT part of the standard ACAS architecture?
A) Nessus Scanner
B) Tenable.sc (SecurityCenter)
C) Tenable.io Cloud Platform
D) Nessus Agents
Correct Answer: C
Rationale: The standard ACAS architecture includes Nessus Scanners (active scanning), Tenable.sc (central
management and analysis), Nessus Agents (endpoint-based scanning), and the Patch Repository.
The Tenable.io Cloud Platform is Tenable's commercial cloud offering and is not part of the DoD's on-
premises ACAS implementation .
Question 3
According to the ACAS Best Practices Guide, how many import repositories can you select for a single
scan?
A) Only one
B) A maximum of three
C) You can select all your available repositories
D) As many as you like, if none of them are agent repositories
Correct Answer: A
Rationale: The ACAS Best Practice Guide specifies that a single scan can only be configured with one
import repository. This limitation ensures data consistency and prevents potential conflicts when
vulnerability findings are stored across multiple repositories .
Question 4
What is the recommended maximum number of concurrent Nessus scanner scans per scanner in
ACAS?
,A) Five
B) Ten
C) Fifteen
D) Twenty
Correct Answer: B
Rationale: According to ACAS best practices, a maximum of ten concurrent scans per Nessus scanner is
recommended to optimize performance and prevent scanning resource exhaustion. Exceeding this limit
can result in scan timeouts, incomplete results, or scanner instability .
Question 5
Which of the following best describes the relationship between Tenable.sc and Nessus scanners?
A) Tenable.sc is a replacement for Nessus scanners
B) Tenable.sc manages and aggregates data from Nessus scanners and agents
C) Nessus scanners are the only data source for Tenable.sc
D) Tenable.sc and Nessus scanners operate independently without integration
Correct Answer: B
Rationale: Tenable.sc (SecurityCenter) serves as the central management and analysis platform that
receives, processes, and visualizes vulnerability data from Nessus scanners and Nessus Agents. It provides
correlation, reporting, and risk analysis capabilities. Option A is incorrect as both components serve
distinct functions; Option C is incorrect because agents also provide data; Option D is false as they are
fully integrated .
Question 6
Per the ACAS Best Practices Guide, what is the purpose of the Patch Repository?
A) To store operating system patches for deployment
B) To distribute custom DISA scan policies and audit files
C) To serve as a backup for all ACAS system data
D) To provide software updates for the Tenable.sc platform
Correct Answer: B
Rationale: The Patch Repository in ACAS distributes custom DISA scan policies, audit files, and other
configuration files required for DoD-specific scanning. It is not used for operating system patches (A),
backup (C), or Tenable.sc software updates (D) .
, Question 7
Which ACAS component is responsible for performing active vulnerability and compliance scanning?
A) Tenable.sc
B) Nessus Agent
C) Nessus Scanner
D) Patch Repository
Correct Answer: C
Rationale: The Nessus Scanner is the ACAS component that performs active vulnerability and compliance
scanning. It initiates network-based scans against target systems. While Nessus Agents also perform
scanning, they are endpoint-based and considered passive/reactive .
Question 8
According to the ACAS Task Order 20-0020, which document defines the official requirements for
ACAS implementation?
A) DoD Instruction 8510.01
B) TASKORD 20-0020
C) NIST SP 800-53
D) DISA STIG
Correct Answer: B
Rationale: TASKORD 20-0020 is the specific Task Order that defines implementation requirements for the
Assured Compliance Assessment Solution within the DoD. While other documents relate to cybersecurity
(DoDI 8510.01 for RMF, NIST standards, DISA STIGs), they are not the primary definition document for
ACAS implementation .
Question 9
What is the recommended scan policy for credentialed vulnerability scanning in ACAS?
A) OS Discovery
B) Web Application Tests
C) Vulnerability
D) Differential
Correct Answer: C
Rationale: The "Vulnerability" scan policy (custom DISA policy) is the recommended policy for
credentialed vulnerability scanning. It has most or all plugin families enabled to provide comprehensive
Comprehensive 150-Question Practice Exam
Exam Title:
Assured Compliance Assessment Solution (ACAS) Best Practice Knowledge Examination:
Comprehensive Assessment of Vulnerability Management, Configuration Scanning, and Compliance
Framework Implementation for DoD Cybersecurity Professionals
EXAMINATION INSTRUCTIONS
This examination consists of 150 multiple-choice questions designed to assess comprehensive
knowledge of the ACAS Best Practice Guide and associated Task Orders (TASKORD 20-0020 and
FRAGOs). The exam covers all six knowledge domains (Exams 1-6) and is intended for cybersecurity
professionals responsible for implementing, managing, and maintaining ACAS within Department of
Defense environments.
Time Allowed: 180 minutes
Passing Score: 75%
Reference Materials: ACAS Best Practices Guide, TASKORD 20-0020, FRAGOs 1-
3, Tenable.sc Documentation
SECTION 1: ACAS FUNDAMENTALS AND ARCHITECTURE (Questions
1-25)
Question 1
What is the primary purpose of the Assured Compliance Assessment Solution (ACAS) within the
Department of Defense?
A) To replace all existing network monitoring tools with a single unified platform
B) To provide automated vulnerability assessment and configuration compliance scanning for DoD
networks
C) To manage user authentication and access control across all DoD systems
D) To serve as a replacement for traditional antivirus software
,Correct Answer: B
Rationale: ACAS is the DoD's enterprise solution for automated vulnerability assessment and
configuration compliance scanning. It is designed to identify security weaknesses, verify compliance with
security policies, and provide risk-based prioritization for remediation efforts. Options A, C, and D
describe functions not associated with ACAS's core mission.
Question 2
Which of the following components is NOT part of the standard ACAS architecture?
A) Nessus Scanner
B) Tenable.sc (SecurityCenter)
C) Tenable.io Cloud Platform
D) Nessus Agents
Correct Answer: C
Rationale: The standard ACAS architecture includes Nessus Scanners (active scanning), Tenable.sc (central
management and analysis), Nessus Agents (endpoint-based scanning), and the Patch Repository.
The Tenable.io Cloud Platform is Tenable's commercial cloud offering and is not part of the DoD's on-
premises ACAS implementation .
Question 3
According to the ACAS Best Practices Guide, how many import repositories can you select for a single
scan?
A) Only one
B) A maximum of three
C) You can select all your available repositories
D) As many as you like, if none of them are agent repositories
Correct Answer: A
Rationale: The ACAS Best Practice Guide specifies that a single scan can only be configured with one
import repository. This limitation ensures data consistency and prevents potential conflicts when
vulnerability findings are stored across multiple repositories .
Question 4
What is the recommended maximum number of concurrent Nessus scanner scans per scanner in
ACAS?
,A) Five
B) Ten
C) Fifteen
D) Twenty
Correct Answer: B
Rationale: According to ACAS best practices, a maximum of ten concurrent scans per Nessus scanner is
recommended to optimize performance and prevent scanning resource exhaustion. Exceeding this limit
can result in scan timeouts, incomplete results, or scanner instability .
Question 5
Which of the following best describes the relationship between Tenable.sc and Nessus scanners?
A) Tenable.sc is a replacement for Nessus scanners
B) Tenable.sc manages and aggregates data from Nessus scanners and agents
C) Nessus scanners are the only data source for Tenable.sc
D) Tenable.sc and Nessus scanners operate independently without integration
Correct Answer: B
Rationale: Tenable.sc (SecurityCenter) serves as the central management and analysis platform that
receives, processes, and visualizes vulnerability data from Nessus scanners and Nessus Agents. It provides
correlation, reporting, and risk analysis capabilities. Option A is incorrect as both components serve
distinct functions; Option C is incorrect because agents also provide data; Option D is false as they are
fully integrated .
Question 6
Per the ACAS Best Practices Guide, what is the purpose of the Patch Repository?
A) To store operating system patches for deployment
B) To distribute custom DISA scan policies and audit files
C) To serve as a backup for all ACAS system data
D) To provide software updates for the Tenable.sc platform
Correct Answer: B
Rationale: The Patch Repository in ACAS distributes custom DISA scan policies, audit files, and other
configuration files required for DoD-specific scanning. It is not used for operating system patches (A),
backup (C), or Tenable.sc software updates (D) .
, Question 7
Which ACAS component is responsible for performing active vulnerability and compliance scanning?
A) Tenable.sc
B) Nessus Agent
C) Nessus Scanner
D) Patch Repository
Correct Answer: C
Rationale: The Nessus Scanner is the ACAS component that performs active vulnerability and compliance
scanning. It initiates network-based scans against target systems. While Nessus Agents also perform
scanning, they are endpoint-based and considered passive/reactive .
Question 8
According to the ACAS Task Order 20-0020, which document defines the official requirements for
ACAS implementation?
A) DoD Instruction 8510.01
B) TASKORD 20-0020
C) NIST SP 800-53
D) DISA STIG
Correct Answer: B
Rationale: TASKORD 20-0020 is the specific Task Order that defines implementation requirements for the
Assured Compliance Assessment Solution within the DoD. While other documents relate to cybersecurity
(DoDI 8510.01 for RMF, NIST standards, DISA STIGs), they are not the primary definition document for
ACAS implementation .
Question 9
What is the recommended scan policy for credentialed vulnerability scanning in ACAS?
A) OS Discovery
B) Web Application Tests
C) Vulnerability
D) Differential
Correct Answer: C
Rationale: The "Vulnerability" scan policy (custom DISA policy) is the recommended policy for
credentialed vulnerability scanning. It has most or all plugin families enabled to provide comprehensive