DISA ACAS ACTUAL EXAM SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
▶ What is the maximum size of a Tenable.sc Repository?
a. 16 GB
b. 32 GB
c. 64 GB
d. 128 GB. Answer: 64 GB
▶ T/F
The IP address(es) you are scanning must be contained in both the
definition of the scan zone and the definition of the repository.
a. True
b. False. Answer: True
▶ What Tenable.sc role is responsible for setting up scan zones?
a. Administrator
b. Manager
c. SecurityManager
d. End User. Answer: Administrator
▶ Per the ACAS contract, how can you get your Tenable.sc plugin
updates?
a. Automatically, from DISA's plugin server
b. Manually from the DoD Patch Repository
c. Download a copy from the vendor. Answer: - Automatically, from DISA's
plugin server
- Manually from the DoD Patch Repository
, ▶ According to the ACAS contract, what are the three allowable options for
scanning stand-alone networks?. Answer: 1. Download Tenable and
Nessus on Lunix system
2. Use VM for both
3. Remove Nessus scanner and leave Tenable, place in an isolated
scanning environment
▶ Plugins are grouped into families, such as:
a. AIX Local Security Checks
b. Windows
c. Red Hat Local Security Checks
d. SCADA
e. All of the above. Answer: All of the above
▶ 1-4Components of an Active Vulnerability Scan consist of: a scan policy,
schedule, credentials, scan zone, import repository, and __________.
Select the best answer.
a. User Role
b. Targets
c. Assurance Report Card
d. Query. Answer: Targets
▶ _________ are administrative-level usernames and passwords (or SSH
keypairs) used in authenticated scans? Select the best answer.
a. Audit Files
b. Scan Policies
c. Credentials
d. Asset Lists. Answer: Credentials
▶ Networks using Dynamic Host Configuration Protocol (DHCP) require
that this Active Scan setting be enabled to properly track endpoints.
a. Remove vulnerabilities from scanned hosts that have been inactive for
(X days)
b. Track hosts which have been issued new IP addresses
QUESTIONS WITH SOLUTIONS GRADED A+
▶ What is the maximum size of a Tenable.sc Repository?
a. 16 GB
b. 32 GB
c. 64 GB
d. 128 GB. Answer: 64 GB
▶ T/F
The IP address(es) you are scanning must be contained in both the
definition of the scan zone and the definition of the repository.
a. True
b. False. Answer: True
▶ What Tenable.sc role is responsible for setting up scan zones?
a. Administrator
b. Manager
c. SecurityManager
d. End User. Answer: Administrator
▶ Per the ACAS contract, how can you get your Tenable.sc plugin
updates?
a. Automatically, from DISA's plugin server
b. Manually from the DoD Patch Repository
c. Download a copy from the vendor. Answer: - Automatically, from DISA's
plugin server
- Manually from the DoD Patch Repository
, ▶ According to the ACAS contract, what are the three allowable options for
scanning stand-alone networks?. Answer: 1. Download Tenable and
Nessus on Lunix system
2. Use VM for both
3. Remove Nessus scanner and leave Tenable, place in an isolated
scanning environment
▶ Plugins are grouped into families, such as:
a. AIX Local Security Checks
b. Windows
c. Red Hat Local Security Checks
d. SCADA
e. All of the above. Answer: All of the above
▶ 1-4Components of an Active Vulnerability Scan consist of: a scan policy,
schedule, credentials, scan zone, import repository, and __________.
Select the best answer.
a. User Role
b. Targets
c. Assurance Report Card
d. Query. Answer: Targets
▶ _________ are administrative-level usernames and passwords (or SSH
keypairs) used in authenticated scans? Select the best answer.
a. Audit Files
b. Scan Policies
c. Credentials
d. Asset Lists. Answer: Credentials
▶ Networks using Dynamic Host Configuration Protocol (DHCP) require
that this Active Scan setting be enabled to properly track endpoints.
a. Remove vulnerabilities from scanned hosts that have been inactive for
(X days)
b. Track hosts which have been issued new IP addresses