DISA ACAS EXAM STUDY GUIDE 2026
COMPLETE QUESTIONS WITH ANSWERS
GUARANTEED TO PASS
▶ Which of these are key drivers of the Vulnerability Priority Ratings
(VPR)? Select from the following.
a. Vulnerability Age
b. Exploit Code Maturity
c. Threat Sources
d. Threat Intensity
e. All of the above. Answer: All of the above
▶ T/F
A vulnerability will be marked as mitigated if a subsequent scan determines
that the vulnerability is no longer present on the endpoint.. Answer: True
▶ 2-2 T/F
Nessus Agents are lightweight Nessus scanners installed on the endpoint..
Answer: True
▶ Agent scans are scheduled/run from which of the following?
a. Nessus Manager
b. Nessus Network Monitor
c. Tenable.sc. Answer: Nessus Manager
▶ An Agent Differential Scan should be run on endpoints with or without
Agents?
a. With agents
b. Without agents
c. All of the above. Answer: With agents
▶ T/F
, A Nessus Manager requires a license that you can obtain from the DEPS
portal.. Answer: True
▶ 2-3
Systems and devices are compliant when they are _________.
a. Secure
b. Properly configured in accordance with Center for Internet Security
requirements
c. Patched
d. In accordance with established guidelines, specifications or legislation.
Answer: In accordance with established guidelines, specifications or
legislation
▶ T/F
Compliance auditing identifies deviations from a defined standard,
whereas, vulnerability management finds weaknesses that could lead to
compromise.. Answer: True
▶ T/F
If your system is compliant, there is no way it can suffer a security breach..
Answer: False
▶ T/F
ACAS TASKORD 20-0020 FRAGO 2 clarifies that only DISA STIG Tenable
Audit files are to be used for configuration scanning in ACAS.. Answer:
True
▶ Choose the Tenable.sc Severity Level that corresponds to the Failed
Compliance result.
a. Critical
b. High
c. Medium
d. Low
e. Informational. Answer: High
▶ Per the ACAS Best Practices Guide, which of the following Tenable.sc
resources are proprietary formatted XML files that define how ACAS should
check for compliance with a specified STIG?
COMPLETE QUESTIONS WITH ANSWERS
GUARANTEED TO PASS
▶ Which of these are key drivers of the Vulnerability Priority Ratings
(VPR)? Select from the following.
a. Vulnerability Age
b. Exploit Code Maturity
c. Threat Sources
d. Threat Intensity
e. All of the above. Answer: All of the above
▶ T/F
A vulnerability will be marked as mitigated if a subsequent scan determines
that the vulnerability is no longer present on the endpoint.. Answer: True
▶ 2-2 T/F
Nessus Agents are lightweight Nessus scanners installed on the endpoint..
Answer: True
▶ Agent scans are scheduled/run from which of the following?
a. Nessus Manager
b. Nessus Network Monitor
c. Tenable.sc. Answer: Nessus Manager
▶ An Agent Differential Scan should be run on endpoints with or without
Agents?
a. With agents
b. Without agents
c. All of the above. Answer: With agents
▶ T/F
, A Nessus Manager requires a license that you can obtain from the DEPS
portal.. Answer: True
▶ 2-3
Systems and devices are compliant when they are _________.
a. Secure
b. Properly configured in accordance with Center for Internet Security
requirements
c. Patched
d. In accordance with established guidelines, specifications or legislation.
Answer: In accordance with established guidelines, specifications or
legislation
▶ T/F
Compliance auditing identifies deviations from a defined standard,
whereas, vulnerability management finds weaknesses that could lead to
compromise.. Answer: True
▶ T/F
If your system is compliant, there is no way it can suffer a security breach..
Answer: False
▶ T/F
ACAS TASKORD 20-0020 FRAGO 2 clarifies that only DISA STIG Tenable
Audit files are to be used for configuration scanning in ACAS.. Answer:
True
▶ Choose the Tenable.sc Severity Level that corresponds to the Failed
Compliance result.
a. Critical
b. High
c. Medium
d. Low
e. Informational. Answer: High
▶ Per the ACAS Best Practices Guide, which of the following Tenable.sc
resources are proprietary formatted XML files that define how ACAS should
check for compliance with a specified STIG?