The central console that provides continuous asset- Tenable.sc
based security and compliance monitoring is
____________.
The tool that probes hosts and does active vulnerability Nessus Active Vulnerability Scanner
and compliance scanning is ______________________
The tool that can manage scan data, run scans and pull Nessus Manager
in data from various Nessus Agent is the
________________.
The Passive Scanner that detects vulnerabilities by Nessus Network Monitor
sniffing network traffic is the
__________________________________________.
What is ACAS? ACAS is a network-based security compliance and assessment capability
designed to provide awareness of the security posture and network health of
DoD networks
What is the task order for the implementation of 20-0020
enterprise use of ACAS?
T/F FALSE
A vulnerability is a weakness of attack that can
compromise your system A vulnerability is not an attack, it is a weakness
T/F TRUE
The Nessus scanner monitors data at rest, while the
NNM monitors data in motion
A lightweight program installed on the host that gives you A Nessus Agent
visibility into other IT assets that connect intermittently to
the internet
Which page loads by default when you log into Dashboard
Tenable.sc?
Which of the following pages displays the update Feeds
schedule for updating the active and passive plugins on
security manager's interface?
Which page allows you to set your local time zone? Profile
What can you do on the plugins page of Tenable.sc? Search for specific plugins, view plugin details and source and upload custom
plugins
A group of users responsible for a specific number of Organization
assets is an _______________.
A defined static range of IP addresses with an Scan Zone
associated Nessus scanner is called a
_____________________.
A set of proprietary data files that stores scan results and Repository
resides on the Tenable.sc is known as a
_____________________.
, ACAS Study Guide
A script file used to collect and interpret vulnerability, Plugin
compliance and configuration is a ____________.
What is the maximum size of a Tenable.sc repository? 32 GB
T/F True
The IP address you are scanning must be contained in
both the definition of the scan zone and the definition of
the repository
What Tenable.sc role is responsible for setting up scan Administrator
zones?
Per the ACAS contract, how can you get your Tenable.sc Automatically from DISA's plugin server or manually form the DoD patch
plugin updates? repository
According to the ACAS contract, what are the three 1) Install both Nessus and Tenable on a Lunix system using the ACAS kickstart
allowable options for scanning stand alone networks?
2) Configure a windows OS with VM software, installing both Tenable and
Nessus on the virtual machines
3) Detach the Nessus system from Tenable and place it in the isolated enclave
for scanning. Once Scanning is complete, reattach Nessus to the tenable and
manually upload scan results
Components of an actve vulnerability scan consist of: a Targets
scan policy, schedule, credentials, scan zone, import
repo and ________________.
____________ are administrative-level usernames and Credentials
passwords (or SSH keypairs) used in authenticated
scans?
Networks using dynamic host configuration protocol Track hosts which have been issued new IP addresses
(SHCP) require that this active scan setting be enabled
to properly track hosts.
Which type of scan is able to run local checks? Credentialed
T/F TRUE
You may only select one import repository per scan
T/F FALSE
Once an active scan is running, you can't pause or stop -Scans can be paused easily through the Tenable.sc user interface
it
Which port scan range value tells the scanner to scan Default
only common ports?
___________ directs the scanner to target a specific Port scan range
range of ports.
____________ limits the maximum number of targets Max simultaneous checks per scan
that a single nessus scanner will scan at the same time.