wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Eval stuff VMO

Total questions: 70

Worksheet time: 35mins

Name
Class
Date
1.

What is a group of users responsible for specific set of hosts?

a. Organization

b. Plugin

c. Repository

d. Scan Zone

a)

a. Organization

b)

b. Plugin

c)

c. Repository

d)

d. Scan Zone

2.

A scan zone __________.

a. Maintains a database of vulnerability data defined by assets or IP addresses

b. Associates an IP address or range of IP addresses with one or more scanners

c. Groups users who are responsible for a specific set of hosts

d. Runs a script file used to collect and interpret vulnerability, compliance, and configuration data

a)

a. Maintains a database of vulnerability data defined by assets or IP addresses

b)

b. Associates an IP address or range of IP addresses with one or more scanners

c)

c. Groups users who are responsible for a specific set of hosts

d)

d. Runs a script file used to collect and interpret vulnerability, compliance, and configuration data

3.

What contains vulnerability information, a simplified set of remediation actions and the algorithm to test for the presence of the security issue? a. Audit File

b. Organization

c. Plugin

d. Vulnerability Index

a)

a. Audit File

b)

b. Organization

c)

c. Plugin

d)

d. Vulnerability Index

4.

Which of the following is NOT a Security Center severity code?

a. Critical

b. Info

c. Low

d. Severe

a)

a. Critical

b)

b. Info

c)

c. Low

d)

d. Severe

5.

What component of ACAS performs evaluates processes running on the host or probes the host’s network services? a. Nessus scanners b. Plugins c. Passive Vulnerability Scanners (PVS) d. SecurityCenters

a)

a. Nessus scanners

b)

b. Plugins

c)

c. Passive Vulnerability Scanners (PVS)

d)

d. SecurityCenters

6.

What is the weight of a CAT II vulnerability? a. 0 b. 1 c. 4 d. 10

a)

a. 0

b)

b. 1

c)

c. 4

d)

d. 10

7.

What is the weight for a CAT I vulnerability? a. 0 b. 1 c. 4 d. 10

a)

a. 0

b)

b. 1

c)

c. 4

d)

d. 10

8.

Which role enables personnel to only create vulnerability reports within the repositories of the base with least privilege? a. Administrator b. Security Manager c. Scanning Technician d. Read-Only

a)

a. Administrator

b)

b. Security Manager

c)

c. Scanning Technician

d)

d. Read-Only

9.

Which SecurityCenter role has the ability to launch scans, configure users, vulnerability policies, and other objects belonging to their organization? a. Administrator b. Executive c. Scanning Technician d. Security Manager

a)

a. Administrator

b)

b. Executive

c)

c. Scanning Technician

d)

d. Security Manager

10.

Within the Targets section of Active Scan settings, which IP addresses can be scanned? a. Both IPv6 and IPv4 addresses simultaneously. b. Either IPv6 or IPv4 addresses. c. Only IPv6 addresses. d. Only IPv4 addresses.

a)

a. Both IPv6 and IPv4 addresses simultaneously.

b)

b. Either IPv6 or IPv4 addresses.

c)

c. Only IPv6 addresses.

d)

d. Only IPv4 addresses.

11.

How often should the SecurityCenter automatically update plugins? a. Daily b. Weekly c. Bi-weekly d. Monthly

a)

a. Daily

b)

b. Weekly

c)

c. Bi-weekly

d)

d. Monthly

12.

Which scan type is used to identify online endpoints at a given period? a. Targeted b. Compliance c. Discovery d. Vulnerability

a)

a. Targeted

b)

b. Compliance

c)

c. Discovery

d)

d. Vulnerability

13.

_____ scans are specialized scans performed in response to a newly identified threat or to validate compliance with an order. a. Vulnerability b. Compliance c. Discovery d. Targeted

a)

a. Vulnerability

b)

b. Compliance

c)

c. Discovery

d)

d. Targeted

14.

Which type of scan determines all vulnerabilities found on live hosts within a network enclave? a. Discovery b. Vulnerability c. Compliance d. Targeted

a)

a. Discovery

b)

b. Vulnerability

c)

c. Compliance

d)

d. Targeted

15.

What determines what a user can or cannot access from their ACAS account? a. Authorizations b. Permissions c. Credentials d. Roles

a)

a. Authorizations

b)

b. Permissions

c)

c. Credentials

d)

d. Roles

16.

What role is responsible for configuration tasks such as defining organizations, repositories, and Nessus scanners? a. Administrator b. Auditor c. Credential manager d. Security manager

a)

a. Administrator

b)

b. Auditor

c)

c. Credential manager

d)

d. Security manager

17.

When viewing plugin details, which of the following can be observed? a. The CVE and the BID. b. The BID only. c. The CVE only. d. Neither the CVE nor BID.

a)

a. The CVE and the BID.

b)

b. The BID only

c)

c. The CVE only.

d)

d. Neither the CVE nor BID.

18.

Which type of asset list are flexible groups of condition statements that refresh using the results from scans? a. MAC Address b. DNS Name c. Dynamic d. Static

a)

a. MAC Address

b)

b. DNS Name

c)

c. Dynamic

d)

d. Static

19.

Which formula is used to determine the failed access rate for a completed scan? a. Good/Bad b. Good/(Good+Bad) c. Bad/Good d. Bad/(Good+Bad)

a)

a. Good/Bad

b)

b. Good/(Good+Bad)

c)

c. Bad/Good

d)

d. Bad/(Good+Bad)

20.

Plugins for SecurityCenter can be downloaded automatically or downloaded manually from ___________. a. AFCEDs b. Air Force Portal c. DoD Patch Repository d. Nessus Patch Repository

a)

a. AFCEDs

b)

b. Air Force Portal

c)

c. DoD Patch Repository

d)

d. Nessus Patch Repository

21.

Which type of scan should not use a dynamic asset list? a. Discovery b. Vulnerability c. Compliance d. Targeted

a)

a. Discovery

b)

b. Vulnerability

c)

c. Compliance

d)

d. Targeted

22.

Do NOT scan more than hosts in a single targeted scan. a. 2,500 b. 5,000 c. 7,500 d. 10,000

a)

a. 2,500

b)

b. 5,000

c)

c. 7,500

d)

d. 10,000

23.

What contains additional settings for active scans including plugin settings and advanced directives? a. Asset List b. Repository c. Scan Policy d. Scan Zone

a)

a. Asset List

b)

b. Repository

c)

c. Scan Policy

d)

d. Scan Zone

24.

What is a database within Tenable.sc that contains vulnerability data? a. Asset List b. Organization c. Repository d. Scan Zone

a)

a. Asset List

b)

b. Organization

c)

c. Repository

d)

d. Scan Zone

25.

 What should the max scan duration be set to? a. 24 Hours b. 12 Hours c. 40 Hours d. 20 Hours 

a)

a. 24 Hours

b)

b. 12 Hours

c)

c. 40 Hours

d)

d. 20 Hours

26.

Which executable installs the Configuration Manager client? a. CCMSetup.exe b. CCMInstallClient.exe c. RunCCM.exe d. SetupCCM.exe

a)

a. CCMSetup.exe

b)

b. CCMInstallClient.exe

c)

c. RunCCM.exe

d)

d. SetupCCM.exe

27.

_____ is a site system role that contains source files for clients to download. a. Distribution Point b. Management Point c. SMS Provider d. Software Update Point

a)

a. Distribution Point

b)

b. Management Point

c)

c. SMS Provider

d)

d. Software Update Point

28.

_____ is a site system role that provides policy and service location information to clients and receives configuration data from clients. a. Distribution Point b. Management Point c. SMS Provider d. Software Update Point

a)

a. Distribution Point

b)

b. Management Point

c)

c. SMS Provider

d)

d. Software Update Point

29.

____ helps monitor client installation and identifies clients that are unmanaged because they can't communicate with their management point.

a)

a. Distribution Point

b)

b. Fallback Status Point

c)

c. SMS Provider

d)

d. Software Update Point

30.

The _____ is the interface between a Configuration Manager console and the site database. a. Client Management Point b. Management Point c. SMS Provider d. Software Update Point

a)

a. Client Management

b)

b. Management Point

c)

c. SMS Provider

d)

d. Software Update Point

31.

_____ is a site system role that integrates with Windows Server Update Services (WSUS) to provide software updates to Configuration Manager clients. a. Client Management Point b. Management Point c. SMS Provider d. Software Update Point

a)

a. Client Management Point

b)

b. Management Point

c)

c. SMS Provider

d)

d. Software Update Point

32.

Which of the following is considered a membership rule for device collections? a. Direct b. Reporting c. Monitoring d. Windows

a)

a. Direct

b)

b. Reporting

c)

c. Monitoring

d)

d. Windows

33.

In the MECM console, device collections are located in the __________ directory. a. Administration b. Assets and Compliance c. Monitoring d. Software Library

a)

a. Administration

b)

b. Assets and Compliance

c)

c. Monitoring

d)

d. Software Library

34.

In the MECM console, Software Updates are located in the __________ directory. a. Administration b. Assets and Compliance c. Monitoring d. Software Library

a)

a. Administration

b)

b. Assets and Compliance

c)

c. Monitoring

d)

d. Software Library

35.

In the MECM console, Reports are located in the __________ directory. a. Administration b. Assets and Compliance c. Monitoring d. Software Library

a)

a. Administration

b)

b. Assets and Compliance

c)

c. Monitoring

d)

d. Software Library

36.

In the MECM console, Site Configuration is located in the __________ directory. a. Administration b. Assets and Compliance c. Monitoring d. Software Library

a)

a. Administration

b)

b. Assets and Compliance

c)

c. Monitoring

d)

d. Software Library

37.

Which type of MECM site sits locally at each base? a. Remote Distribution Point b. Central Administration Site c. Primary Site d. Secondary Site

a)

a. Remote Distribution Point

b)

b. Central Administration Site

c)

c. Primary Site

d)

d. Secondary Site

38.

Where is the Central Administration server physically located? a. Scott APC b. Wright Patterson APC c. Peterson RDC d. Joint Base Pearl Harbor Hickam

a)

a. Scott APC

b)

b. Wright Patterson APC

c)

c. Peterson RDC

d)

d. Joint Base Pearl Harbor Hickam

39.

Within the Client Configuration Manager Properties which action would you initiate to retrieve the most up-to date client policy? a. Software Inventory Cycle b. User Policy Retrieval & Evaluation Cycle c. Machine Policy Retrieval & Evaluation Cycle d. Application Deployment Evaluation Cycle

a)

a. Software Inventory Cycle

b)

b. User Policy Retrieval & Evaluation Cycle

c)

c. Machine Policy Retrieval & Evaluation Cycle

d)

d. Application Deployment Evaluation Cycle

40.

Where could a user go to install software that was deployed via MECM? a. Distribution Point b. Security Center c. Software Center d. Software Update Point

a)

a. Distribution Point

b)

b. Security Center

c)

c. Software Center

d)

d. Software Update Point

41.

Where is the client log file CCMEval.log located on the machine? a. /var/log b. D:\ c. C:\Windows\CCM\Logs d. C:\Windows\ccmsetup

a)

a. /var/log

b)

b. D:\

c)

c. C:\Windows\CCM\Logs

d)

d. C:\Windows\ccmsetup

42.

CMTrace.exe is located in what Windows client folder location? a. C:\Windows\SysWOW64\CCM\Trace\CMTrace.exe b. C:\Windows\RemotePackages\CMTrace.exe c. C:\Windows\ccmsetup\CMTrace.exe d. C:\Windows\CCM\CMTrace.exe

a)

a. C:\Windows\SysWOW64\CCM\Trace\CMTrace.exe

b)

b. C:\Windows\RemotePackages\CMTrace.exe

c)

c. C:\Windows\ccmsetup\CMTrace.exe

d)

d. C:\Windows\CCM\CMTrace.exe

43.

MECM uses groups of users or devices called ___________. a. Collections b. Asset Lists c. Libraries d. Logs

a)

a. Collections

b)

b. Asset Lists

c)

c. Libraries

d)

d. Logs

44.

44. There are 4 Primary Site Suites located at Wright Patterson APC and 4 Primary Site Suites located at _______________. a. Peterson RDC b. Scott APC c. Joint Base Langley-Eustis d. Joint Base Pearl Harbor Hickam

a)

a. Peterson RDC

b)

b. Scott APC

c)

c. Joint Base Langley-Eustis

d)

d. Joint Base Pearl Harbor Hickam

45.

What would you use to filter a new collection to only show results from a single base? a. Management Point b. Machine Policy Update c. Limiting Collection d. CM Trace

a)

a. Management Point

b)

b. Machine Policy Update

c)

c. Limiting Collection

d)

d. CM Trace

46.

A(n) _____ rule’s membership doesn’t change unless a resource is removed from Configuration Manager and require more administrative overhead than query rule collections because they require manual changes. a. Exclude Collection b. Include Collection c. Direct d. Static

a)

a. Exclude Collection

b)

b. Include Collection

c)

c. Direct

d)

d. Static

47.

A(n) _____ rule’s membership will dynamically update the membership of a collection which runs on a schedule. a. Dynamic b. Query c. Direct d. Static

a)

a. Dynamic

b)

b. Query

c)

c. Direct

d)

d. Static

48.

Which website hosts SDC (Standard Desktop Configurations) for approved Department of Defense software products? a. https://www.my.af.mil b. https://ceds.gunter.af.mil c. https://gunter.sdc.af.mil d. http://gunter.ceds.af.mil

a)

https://www.my.af.mil

b)

https://ceds.gunter.af.mil

c)

https://gunter.sdc.af.mil

d)

http://gunter.ceds.af.mil

49.

In regards to content distribution, which component transfers the package to the distribution point? a. Despooler b. Data Transfer Service c. File Transfer Service d. Package Transfer Manager

a)

Despooler

b)

Data Transfer Service

c)

File Transfer Service

d)

Package Transfer Manager

50.

Which component of CcmExec is responsible for downloading files via BITS? a. Despooler b. Data Transfer Service c. File Transfer Service d. Package Transfer Manager

a)

Despooler

b)

Data Transfer Service

c)

File Transfer Service

d)

Package Transfer Manager

51.

Which component of the Software Update Scan checks the registry to ensure Group Policy does NOT override the update server? a. Scan Agent b. WSUS Server c. WUAHandler d. Location Services

a)

a. Scan Agent

b)

b. WSUS Server

c)

c. WUAHandler

d)

d. Location Services

52.

______ is a container that stores specific information. a. Configuration Item b. Detection Item c. Setting d. Compliance Rules

a)

a. Configuration Item

b)

b. Detection Item

c)

c. Setting

d)

d. Compliance Rules

53.

_____ detects whether an application is installed and uses the windows installer file for the application or by custom script. a. Configuration Item b. Detection Item c. Setting d. Compliance Rules

a)

a. Configuration Item

b)

b. Detection Item

c)

c. Setting

d)

d. Compliance Rules

54.

What specifies the condition that defines the compliance of a configuration item setting? a. Configuration Item b. Detection Item c. Setting d. Compliance Rules

a)

a. Configuration Item

b)

b. Detection Item

c)

c. Setting

d)

d. Compliance Rules

55.

Configuration baselines are used to monitor and remediate _____ a. Non-software Items b. Registry Keys c. Outdated Protocols d. All the Above

a)

a. Non-software Items

b)

b. Registry Keys

c)

c. Outdated Protocols 

d)

d. All the Above

56.

Which of the following is NOT an example of a software requested through a change request? a. Wickr b. TIMS c. GTIMS d. Wireshark

a)

a. Wickr

b)

b. TIMS

c)

c. GTIMS

d)

d. Wireshark

57.

 When AFECMO releases an application, what is the default content location within the imported application? 

a)

a. AFECMO Lab Environment

b)

b. C:\

c)

c. ZHTX-EM-101P

d)

d. ZHTX-EM-101P\Packages

58.

. Which of the following is NOT a default way that MECM can detect an application? a. Registry b. File System c. Product Version d. Windows Installer

a)

a. Registry

b)

b. File System

c)

c. Product Version

d)

d. Windows Installer

59.

Which of the following detection methods within MECM looks for uninstall strings associated with applications? a. Registry b. File System c. Product Version d. Windows Installer

a)

a. Registry

b)

b. File System

c)

c. Product Version

d)

d. Windows Installer

60.

When an application is deployed to a device, what decides what deployment type is used? a. Content Source b. Detection Method c. Product Version d. Requirement

a)

a. Content Source

b)

b. Detection Method

c)

c. Product Version

d)

d. Requirement

61.

Which determines how an application is installed

a)

a. Deployment Type

b)

b. Detection Method

c)

c. Collection

d)

d. Requirement

62.

By default VMOs hide the installation and do NOT give users the ability to postpone installation. The ability to postpone an installation is a part of which component? a. Compliance Item b. Detection Method c. Requirement d. User Experience

a)

a. Compliance Item

b)

b. Detection Method

c)

c. Requirement

d)

d. User Experience

63.

Which MECM client push method requires the computer to be discovered before a MECM client is installed? a. Client Push Installation b. Software Update Point Based Installation c. Group Policy d. Logon Script

a)

a. Client Push Installation

b)

b. Software Update Point Based Installation

c)

c. Group Policy

d)

d. Logon Script

64.

Which client installation method supports using command-line properties for CCMSetup to install? a. Client Push Installation b. Software Update Point Based Installation c. Group Policy d. Logon Script

a)

a. Client Push Installation

b)

b. Software Update Point Based Installation

c)

c. Group Policy

d)

d. Logon Script

65.

Which of the following is NOT downloaded from the distribution point?

a)

a. Application Content

b)

b. Software Packages

c)

c. Software Updates

d)

d. Policy

66.

What is the first thing a client does during a software update deployment? a. Scan Agent request gets created b. Set the WSUS Server c. Scan Agent sends a WSUS Location Request d. Location Services sends its location to the Scan Agent

a)

a. Scan Agent request gets created

b)

b. Set the WSUS Server

c)

c. Scan Agent sends a WSUS Location Request

d)

d. Location Services sends its location to the Scan Agent

67.

Which of the following is NOT an example of a requirement? a. Operator exists b. Application exists c. Active Directory site d. Operating System

a)

a. Operator exists

b)

b. Application exists

c)

c. Active Directory site

d)

d. Operating System

68.

Which of the following log files applies to updates that are for windows OS? a. CAS.log b. ContentTransferManager.log c. CBS.log d. DataTransferService.log

a)

a. CAS.log

b)

b. ContentTransferManager.log

c)

c. CBS.log

d)

d. DataTransferService.log

69.

Which log file would you review if you are troubleshooting unexpected reboots or updates installed outside of a maintenance window? a. CAS.log b. ContentTransferManager.log c. CBS.log d. DataTransferService.log

a)

a. CAS.log

b)

b. ContentTransferManager.log

c)

c. CBS.log

d)

d. DataTransferService.log

70.

Which log files are associated with detection methods? a. CAS.log & CCMEval.log b. CcmMessaging.log & CCMEval.log c. AppDetection.log & Detect.log d. Appenforce.log & Appdiscovery.log

a)

a. CAS.log & CCMEval.log

b)

b. CcmMessaging.log & CCMEval.log

c)

c. AppDetection.log & Detect.log

d)

d. Appenforce.log & Appdiscovery.log