Acronis Certified Engineer (ACE) — Questions and Answers
Question 1: When migrating a workload using Acronis, what does 'seeding' refer to in the context of large data transfers to the cloud?
- Shipping physical storage media to the cloud provider to avoid slow network uploads (Correct answer)
- Setting up the initial replication schedule
- Configuring initial encryption keys for cloud storage
- Initializing the backup catalog on the cloud storage node
Correct answer: Shipping physical storage media to the cloud provider to avoid slow network uploads
Seeding involves copying backup data to physical media and shipping it to the data center to bypass slow or costly internet uploads for very large datasets.
Question 2: Which Acronis feature enables near-instant recovery by running a virtual machine directly from a backup image without performing a full restoration first?
- Acronis PXE Server network boot
- Acronis Instant Restore (Run VM from backup) (Correct answer)
- Acronis Universal Restore with driver injection
- Acronis Startup Recovery Manager
Correct answer: Acronis Instant Restore (Run VM from backup)
Acronis Instant Restore (Run VM from backup) starts a virtual machine directly from the backup image, providing immediate availability while a background migration to permanent storage completes.
Question 3: What is the role of a self-signed certificate in a standalone Acronis Management Server deployment?
- It authenticates the server locally without requiring an external certificate authority (Correct answer)
- It provides stronger encryption than CA-issued certificates
- It is not supported; only CA-signed certificates work
- It is used only for agent-to-agent communication
Correct answer: It authenticates the server locally without requiring an external certificate authority
Self-signed certificates allow a standalone Acronis server to authenticate itself locally without a third-party CA, though browsers will show warnings since it's not trusted by default.
Question 4: During Acronis bare metal recovery, if the target hard drive is larger than the source drive, what option does Acronis provide?
- A partition alignment error occurs that must be corrected manually after recovery
- Acronis offers to proportionally resize partitions to fill the larger disk or retain original sizes (Correct answer)
- The restoration fails and requires source and target drives to be identical in size
- Only the used sectors are restored and the remaining capacity becomes permanently inaccessible
Correct answer: Acronis offers to proportionally resize partitions to fill the larger disk or retain original sizes
When the target disk is larger, Acronis allows proportional resizing of partitions to utilize all available space, or restoring at original sizes while leaving the remaining disk space unallocated.
Question 5: What does 'encryption at rest' mean in the context of Acronis backups?
- Data is encrypted only on the source machine before backup starts
- Data is encrypted while stored in the backup location, regardless of network state (Correct answer)
- Data is encrypted only while being transferred over the network
- Data is encrypted in RAM during processing
Correct answer: Data is encrypted while stored in the backup location, regardless of network state
Encryption at rest means backup data remains encrypted in its storage location, protecting it from unauthorized physical or storage-level access even without network involvement.
Question 6: A forensic backup in Acronis Cyber Protect captures which additional data beyond a standard disk backup?
- Application logs only
- Network traffic captured during the backup window
- Active Directory snapshots
- RAM contents and running process information alongside the disk image (Correct answer)
Correct answer: RAM contents and running process information alongside the disk image
Forensic backups in Acronis capture volatile data including RAM contents and running processes, enabling post-incident investigation alongside the disk image.
Question 7: What does the Acronis Network Discovery feature do?
- Automatically discovers unprotected machines on the network (Correct answer)
- Maps all active firewall rules
- Monitors real-time bandwidth consumption
- Scans machines for open vulnerabilities
Correct answer: Automatically discovers unprotected machines on the network
Acronis Network Discovery scans the local network to automatically find machines that are not yet covered by a protection plan.
Question 8: How does collaboration enhance Client Communication & Training in Acronis Certified Engineer?
- Reduces accountability
- Brings diverse perspectives and improves outcomes (Correct answer)
- Creates meetings
- Slows process
Correct answer: Brings diverse perspectives and improves outcomes
Collaboration brings together different viewpoints leading to better outcomes.
Question 9: When setting up Acronis backup to a cloud destination, what does the 'client-side encryption' option mean?
- Data is encrypted on the source machine before leaving for the cloud, so the cloud provider never sees plaintext (Correct answer)
- Encryption is applied by the cloud provider after receiving the data
- The cloud provider holds the encryption key for easier recovery
- Encryption is negotiated between the cloud and management server dynamically
Correct answer: Data is encrypted on the source machine before leaving for the cloud, so the cloud provider never sees plaintext
Client-side encryption ensures data is encrypted locally before upload, meaning even the cloud storage provider cannot access the plaintext contents of the backup.
Question 10: A company has 100TB of backup data and wants to reduce storage costs. Which Acronis feature should be evaluated first?
- Enabling global deduplication with a managed vault on Acronis Cyber Infrastructure (Correct answer)
- Adding more backup storage nodes
- Switching to differential backups
- Increasing the backup schedule frequency
Correct answer: Enabling global deduplication with a managed vault on Acronis Cyber Infrastructure
Global deduplication on ACI eliminates redundant data across all sources, potentially reducing 100TB to a fraction of its original size.
Question 11: Which Acronis Cyber Protect Console report helps administrators identify storage locations approaching capacity limits?
- Backup Success Rate Report
- Storage Consumption Report (Correct answer)
- Agent Version Compliance Report
- Data Protection Map
Correct answer: Storage Consumption Report
The Storage Consumption Report shows current and trending storage usage per vault, helping administrators proactively manage capacity.
Question 12: Which file system format does Acronis recommend for backup storage volumes on Windows to maximize performance?
- FAT32
- ReFS (Correct answer)
- NTFS
- exFAT
Correct answer: ReFS
ReFS (Resilient File System) is recommended for Acronis backup storage on Windows Server 2016+ due to its integrity streams and faster large-file handling.
Question 13: Which encryption algorithm does Acronis Cyber Protect use by default for backup data encryption?
- RSA-2048
- 3DES-168
- AES-256 (Correct answer)
- Blowfish-128
Correct answer: AES-256
Acronis Cyber Protect uses AES-256 (Advanced Encryption Standard with 256-bit key) as its default encryption algorithm for securing backup data.
Question 14: What action should an Acronis administrator take if the Activity Log shows repeated 'connection timeout' errors for a specific agent?
- Upgrade the management server to the latest version first
- Investigate network connectivity and firewall rules between the agent and the management server (Correct answer)
- Immediately uninstall and reinstall the agent
- Increase the backup retention period for that machine
Correct answer: Investigate network connectivity and firewall rules between the agent and the management server
Repeated connection timeout errors indicate a network-level issue, so the administrator should check firewall rules, routing, and connectivity between the agent and management server.
Question 15: What is Acronis Startup Recovery Manager (ASRM) and what problem does it solve?
- A cloud service that schedules recovery tasks remotely
- A bootable component in the MBR that enables recovery at startup without external media (Correct answer)
- An API endpoint for automating recovery workflow integrations
- A monitoring daemon that validates backup health on a schedule
Correct answer: A bootable component in the MBR that enables recovery at startup without external media
Acronis Startup Recovery Manager installs a bootable recovery environment in the MBR or system partition, allowing recovery mode to be launched at startup without a separate USB drive or disc.
Question 16: Which Acronis feature allows you to run a backup of a VMware VM directly from the ESXi host without installing an agent inside the guest OS?
- CBT-only backup
- Bare-metal restore
- Agentless backup via vSphere API (Correct answer)
- Agent-based backup
Correct answer: Agentless backup via vSphere API
Acronis leverages VMware's vSphere API for Data Protection (VADP) to perform agentless backups at the hypervisor level without a guest agent.
Question 17: What technology does Acronis Active Protection use to detect ransomware activity on protected machines?
- Hash comparison against a cloud-hosted malware database
- Kernel-level system call interception only available on Linux
- Signature-based antivirus scanning of all writes to disk
- Behavioral heuristics that monitor process activity and file modification patterns (Correct answer)
Correct answer: Behavioral heuristics that monitor process activity and file modification patterns
Acronis Active Protection uses behavioral heuristics to identify ransomware-like patterns such as rapid mass file encryption or unusual process behavior, without relying solely on signatures.
Question 18: Which Acronis component can be deployed in a DMZ to provide secure backup connectivity for isolated networks?
- Web Restore Server
- Management Console
- Protection Agent
- Backup Gateway (Correct answer)
Correct answer: Backup Gateway
The Acronis Backup Gateway can be placed in a DMZ to bridge isolated or segmented networks with backup storage securely.
Question 19: Which approach best supports quality in Compliance & Licensing Requirements for Acronis Certified Engineer?
- Systematic evidence-based methods (Correct answer)
- Avoiding checks
- Intuition only
- Rushing
Correct answer: Systematic evidence-based methods
Evidence-based methods provide reliable foundations for quality outcomes.
Question 20: In Acronis Cyber Protect's multi-tier architecture, which component is responsible for storing backup metadata and enabling fast catalog searches?
- Management Server database
- Cloud indexing engine
- Storage Node catalog service (Correct answer)
- Agent local cache
Correct answer: Storage Node catalog service
The Storage Node maintains a catalog service that indexes backup metadata, allowing administrators to quickly search for specific files and versions without reading entire archives.
Question 21: What is the purpose of backup validation in Acronis Cyber Protect?
- It encrypts the backup archive with an additional layer of AES
- It replicates the backup to a secondary location for redundancy
- It verifies data integrity by checking checksums of all backed-up data blocks (Correct answer)
- It tests whether the backup schedule runs on time
Correct answer: It verifies data integrity by checking checksums of all backed-up data blocks
Validation reads every data block in the backup archive and verifies checksums to confirm the archive is not corrupted and can be used for recovery.
Question 22: What Acronis technology allows target machines to load the Acronis recovery environment over the network without any physical bootable media?
- Acronis PXE Server (Correct answer)
- Acronis Cloud Connect gateway
- Acronis File Sync and Share
- Acronis Disk Director partition manager
Correct answer: Acronis PXE Server
Acronis PXE Server enables network booting using the PXE/TFTP protocol, allowing machines to load the Acronis WinPE or Linux recovery environment directly from the network.
Question 23: In Acronis Cyber Protect, what is the recommended approach for backing up encryption keys themselves to prevent loss?
- Maintain a separate secure, offline record of encryption passwords independent of the Acronis system (Correct answer)
- Store the key in Active Directory and let Acronis retrieve it automatically when needed
- Store them in the same encrypted backup archive they protect
- Rely on Acronis Support to recover keys using master decryption credentials
Correct answer: Maintain a separate secure, offline record of encryption passwords independent of the Acronis system
Encryption passwords must be stored separately from the backups they protect — a secure offline record (such as a password manager or printed secure storage) is the recommended approach.
Question 24: A company uses the 3-2-1 backup rule. Which statement correctly describes this rule as implemented in Acronis?
- 3 backups on 2 media types, 1 encrypted
- 3 daily backups, 2 weekly, 1 monthly
- 3 retention versions, 2 sites, 1 cloud archive
- 3 copies of data, 2 on different media, 1 offsite (Correct answer)
Correct answer: 3 copies of data, 2 on different media, 1 offsite
The 3-2-1 rule mandates 3 copies of data stored on 2 different media types with 1 copy kept offsite for disaster resilience.
Question 25: Which Acronis feature prevents a backup archive from being deleted or modified by ransomware or unauthorized users?
- Immutability (Notarization Lock) (Correct answer)
- Backup Validation
- Source-side encryption
- Bandwidth throttling
Correct answer: Immutability (Notarization Lock)
Acronis's immutability feature locks backup archives for a defined period, preventing deletion or modification by any process including ransomware.
Question 26: During a disaster recovery failover in Acronis Cyber Protect Cloud, what is a 'recovery server'?
- The Acronis management server that coordinates recovery tasks
- A cloud VM pre-configured from a backup to become operational during failover (Correct answer)
- A physical server used to restore backups locally
- A secondary Acronis agent installed on the target machine
Correct answer: A cloud VM pre-configured from a backup to become operational during failover
A recovery server in Acronis DR is a cloud-based VM configured from a backup image that becomes active during a failover event.
Question 27: An Acronis protection plan is set to run incremental backups every 4 hours. What is the maximum potential data loss (RPO) in this configuration?
- Up to 1 hour
- Up to 2 hours
- Up to 8 hours
- Up to 4 hours (Correct answer)
Correct answer: Up to 4 hours
With 4-hour incremental intervals, up to 4 hours of data can be lost if a failure occurs just before the next backup.
Question 28: What is the purpose of the SSL/TLS certificate in Acronis Cyber Protect communication between agent and management server?
- To validate the backup integrity checksum
- To authenticate the management server and encrypt the communication channel (Correct answer)
- To compress data during transfer
- To sign backup archives with a digital fingerprint
Correct answer: To authenticate the management server and encrypt the communication channel
SSL/TLS certificates authenticate the management server identity and establish an encrypted channel, preventing man-in-the-middle attacks between agents and the server.
Question 29: Which command-line tool is used to register an Acronis agent with a management server on Linux?
- acronis_agent --register
- acronis-register-agent -s <server-address>
- acropolis --connect
- sudo /usr/lib/Acronis/BackupAndRecovery/sbin/register_agent --create-account (Correct answer)
Correct answer: sudo /usr/lib/Acronis/BackupAndRecovery/sbin/register_agent --create-account
On Linux, agents are registered with the management server using the register_agent utility located in the Acronis installation path.
Question 30: Which Acronis Cyber Protect protection plan option ensures that a backup is taken immediately if a scheduled backup was missed because the machine was powered off?
- Retry on failure
- Pre/post backup commands
- Always-incremental scheme
- Start conditions — missed scheduled backup (Correct answer)
Correct answer: Start conditions — missed scheduled backup
The 'missed scheduled backup' start condition triggers a backup as soon as the machine comes online after a scheduled window was missed.
Question 31: An ACE engineer needs to suppress monitoring alerts for a machine during a planned maintenance window. What is the recommended approach in Acronis Cyber Protect?
- Disable the machine's network adapter
- Delete all alert notification rules
- Uninstall the agent temporarily
- Use the maintenance mode feature to pause alert generation (Correct answer)
Correct answer: Use the maintenance mode feature to pause alert generation
Maintenance mode suspends alert generation for the selected machine without removing the agent or altering protection plans.
Question 32: Which approach best supports quality in Monitoring & Alert Configuration for Acronis Certified Engineer?
- Intuition only
- Avoiding checks
- Systematic evidence-based methods (Correct answer)
- Rushing
Correct answer: Systematic evidence-based methods
Evidence-based methods provide reliable foundations for quality outcomes.
Question 33: When Acronis Cyber Protect transfers backup data to Acronis Cloud, which protocol secures the data in transit?
- TLS 1.2 or higher over HTTPS (Correct answer)
- FTP with FTPS extension
- IPSec tunnel with pre-shared keys
- SSH file transfer protocol (SFTP)
Correct answer: TLS 1.2 or higher over HTTPS
Acronis Cloud transfers use TLS 1.2 or higher over HTTPS, ensuring modern encryption standards protect data during transmission to the cloud storage.
Question 34: Why stay current with Security & Encryption Protocols trends in Acronis Certified Engineer?
- Not necessary
- Trends irrelevant
- Ensures practices remain effective and relevant (Correct answer)
- Only for new pros
Correct answer: Ensures practices remain effective and relevant
Staying current ensures effective and aligned practices.
Question 35: In Acronis Cyber Protect, what happens to backup encryption if you change the encryption password mid-backup-plan?
- Encryption changes are not allowed once a backup plan is active
- All existing archives are automatically re-encrypted with the new password
- Existing archives retain the old password; only new backups use the new password (Correct answer)
- The plan is suspended until all archives are re-encrypted
Correct answer: Existing archives retain the old password; only new backups use the new password
When you change the encryption password, existing backup archives keep the original password while subsequent backup runs use the new password, requiring you to track both.
Question 36: When installing Acronis Cyber Protect on a machine with an existing Acronis True Image installation, what is the recommended procedure?
- Disable True Image's background service before running the Cyber Protect installer
- Use the migration wizard inside Acronis True Image to upgrade in place
- Uninstall Acronis True Image first, then install Acronis Cyber Protect (Correct answer)
- Install Acronis Cyber Protect alongside True Image — both can coexist
Correct answer: Uninstall Acronis True Image first, then install Acronis Cyber Protect
Acronis True Image must be uninstalled before installing Acronis Cyber Protect because the two products cannot coexist on the same machine.
Question 37: In Acronis Cyber Protect, which backup scheme captures only the data that has changed since the last backup of any type, resulting in faster backups but a longer recovery chain?
- Full backup
- Differential backup
- Synthetic full backup
- Incremental backup (Correct answer)
Correct answer: Incremental backup
Incremental backups capture changes since the last backup of any type (full or incremental), making them fast to create but requiring the full chain for recovery.
Question 38: Which Acronis feature uses behavioral analysis to detect ransomware attempting to encrypt files that are being backed up?
- Real-time deduplication engine
- Cryptographic hash comparison module
- Backup verification engine
- Active Protection with AI-based heuristics (Correct answer)
Correct answer: Active Protection with AI-based heuristics
Acronis Active Protection uses AI-driven behavioral analysis to detect ransomware-like encryption patterns in real time and can block the attack and recover affected files from cache.
Question 39: Which Acronis Cyber Protect Cloud capability allows service providers to offer disaster recovery as a managed service, including cloud-hosted recovery servers and VPN connectivity?
- Disaster Recovery add-on for Cyber Protect Cloud (Correct answer)
- Acronis Backup Advanced
- Acronis Universal Restore
- Acronis Snap Deploy
Correct answer: Disaster Recovery add-on for Cyber Protect Cloud
The Disaster Recovery add-on for Acronis Cyber Protect Cloud provides MSPs with cloud failover infrastructure, VPN tunnels, and recovery orchestration for managed DR services.
Question 40: Which Acronis feature allows administrators to keep a cloud standby VM continuously updated with the latest backup data for rapid failover?
- Hot Standby
- Instant Restore
- Cold Standby
- Warm Standby (Correct answer)
Correct answer: Warm Standby
Warm Standby keeps a standby VM in the cloud powered off but regularly updated, enabling fast failover with minimal data loss.
Acronis Certified Engineer (ACE)
The ACE certification validates proficiency in deploying and managing Acronis backup, disaster recovery, security, and cloud solutions. It tests hands-on skills across backup operations, bare metal recovery, encryption, compliance, and audit reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds