ACAS (Assured Compliance
Assessment Solution) Exam Questions
and Answers
ACAS (Assured Compliance Assessment Solution) - Answer-is a network-based security compliance and
assessment capability designed to provide awareness of the security posture and network health of DoD
networks
SecurityCenter - Answer-is the central console for the ACAS system tools and data
ACAS components - Answer-SecurityCenter
Nessus- active scanner
PVS (passive vulnerability scanner) - sniffs the network
3D tool/optional - port 443
ACAS components perform these main functions: - Answer-- Discover assets
- Detect vulnerabilities and data leaks
- Conduct configuration and compliance audits
- Publish findings to Continuous Monitoring and Risk Scoring (CMRS)
, Plug-in - Answer-displays a list of script files used by Nessus/PVS scanners to collect and interpret
vulnerability, compliance, and configuration data
Things that can be scanned for security data - Answer-servers, workstations, peripherals, Mobile device
Management Servers, network servers
PVS (Passive Vulnerability Scanner) - Answer-watches and determines vulnerabilities based on network
traffic, instead of actively scanning
Compliance - Answer-a state of being in accordance with established guidelines, specifications or
legislation, or the process of becoming so
CMRS ( Continuous Monitoring and Risk Scoring) - Answer-a tool to provide DoD component - and
enterprise-level situational awareness by quantitatively displaying an organization's security posture
Task Order 13-670 - Answer-Implementation of ACAS
What is the 1st screen you see when you log in to SecurityCenter? - Answer-Dashboard
SecurityCenter Building Blocks - Answer--Organization
-Role, Group, and User Definition
-Scan Zone (and Nessus Scanners)
-Repository
-Plugin
Organization - Answer-groups of individuals responsible for a set of common assets
Assessment Solution) Exam Questions
and Answers
ACAS (Assured Compliance Assessment Solution) - Answer-is a network-based security compliance and
assessment capability designed to provide awareness of the security posture and network health of DoD
networks
SecurityCenter - Answer-is the central console for the ACAS system tools and data
ACAS components - Answer-SecurityCenter
Nessus- active scanner
PVS (passive vulnerability scanner) - sniffs the network
3D tool/optional - port 443
ACAS components perform these main functions: - Answer-- Discover assets
- Detect vulnerabilities and data leaks
- Conduct configuration and compliance audits
- Publish findings to Continuous Monitoring and Risk Scoring (CMRS)
, Plug-in - Answer-displays a list of script files used by Nessus/PVS scanners to collect and interpret
vulnerability, compliance, and configuration data
Things that can be scanned for security data - Answer-servers, workstations, peripherals, Mobile device
Management Servers, network servers
PVS (Passive Vulnerability Scanner) - Answer-watches and determines vulnerabilities based on network
traffic, instead of actively scanning
Compliance - Answer-a state of being in accordance with established guidelines, specifications or
legislation, or the process of becoming so
CMRS ( Continuous Monitoring and Risk Scoring) - Answer-a tool to provide DoD component - and
enterprise-level situational awareness by quantitatively displaying an organization's security posture
Task Order 13-670 - Answer-Implementation of ACAS
What is the 1st screen you see when you log in to SecurityCenter? - Answer-Dashboard
SecurityCenter Building Blocks - Answer--Organization
-Role, Group, and User Definition
-Scan Zone (and Nessus Scanners)
-Repository
-Plugin
Organization - Answer-groups of individuals responsible for a set of common assets