ACAS Best Practice Knowledge Exam 3
Questions with Verified Correct Answers
According to the ACAS Best Practices Guide/ACAS TASKORD, both Discovery and
Vulnerability Scans are to be credentialed.
True
False
True
Per the TASKORD the organization will conduct discovery scans of the site's assigned
IP space (active and inactive IP addresses and ranges) at least once every how many
days?
Select the best answer (per the Best Practices Guide).
a. 7
b. 14
c. 21
d. 30
d
Which of the custom DISA scan policies on the Patch Repository has most or all the
plugin families enabled?
Select the best answer.
a. OS Discovery
b. Vulnerability
, c. Configuration
d. Differential
b
It has been 8 days since your last full, credentialed vulnerability scan. What is your
current compliance status?
Select the best statement that reflects your compliance status.
a. In compliance because vulnerability scans are only required every 30 days
b. In compliance because vulnerability scans are only required every 14 days
c. Out of compliance because vulnerability scans are required every 7 days.
d. Out of compliance because vulnerability scans required daily.
c
Today is Friday, and you are getting ready to run your weekly vulnerability scans. Your
last discovery scan was performed on Monday.
Select the best statement that describes your compliance status.
a. In compliance because vulnerability scans are to be initiated no less than 14 days
after the discovery scan/operation is "Completed"
b. In compliance because active plugins must be updated no less than 7 days after the
discovery scan/operation is "Completed"
c. Out of compliance because vulnerability scans are to be initiated not later than (NLT)
72 hours after the discovery scan/operation is "Completed"
d. Out of compliance because vulnerability scans are to be initiated no less thank 24
hours after the discovery scan/operation is "Completed"
Questions with Verified Correct Answers
According to the ACAS Best Practices Guide/ACAS TASKORD, both Discovery and
Vulnerability Scans are to be credentialed.
True
False
True
Per the TASKORD the organization will conduct discovery scans of the site's assigned
IP space (active and inactive IP addresses and ranges) at least once every how many
days?
Select the best answer (per the Best Practices Guide).
a. 7
b. 14
c. 21
d. 30
d
Which of the custom DISA scan policies on the Patch Repository has most or all the
plugin families enabled?
Select the best answer.
a. OS Discovery
b. Vulnerability
, c. Configuration
d. Differential
b
It has been 8 days since your last full, credentialed vulnerability scan. What is your
current compliance status?
Select the best statement that reflects your compliance status.
a. In compliance because vulnerability scans are only required every 30 days
b. In compliance because vulnerability scans are only required every 14 days
c. Out of compliance because vulnerability scans are required every 7 days.
d. Out of compliance because vulnerability scans required daily.
c
Today is Friday, and you are getting ready to run your weekly vulnerability scans. Your
last discovery scan was performed on Monday.
Select the best statement that describes your compliance status.
a. In compliance because vulnerability scans are to be initiated no less than 14 days
after the discovery scan/operation is "Completed"
b. In compliance because active plugins must be updated no less than 7 days after the
discovery scan/operation is "Completed"
c. Out of compliance because vulnerability scans are to be initiated not later than (NLT)
72 hours after the discovery scan/operation is "Completed"
d. Out of compliance because vulnerability scans are to be initiated no less thank 24
hours after the discovery scan/operation is "Completed"