Acronis Certified Engineer (ACE) โ Questions and Answers
Question 1: A VMware backup fails with 'snapshot consolidation error.' What is the most likely root cause?
- CBT is not supported on this version of ESXi
- Residual snapshot files left from a previous failed backup causing delta disk chain issues (Correct answer)
- The VM has no network adapter configured
- Acronis quota exceeded on the backup storage
Correct answer: Residual snapshot files left from a previous failed backup causing delta disk chain issues
Leftover delta VMDK files from a prior failed snapshot cause consolidation errors when Acronis attempts to take a new snapshot.
Question 2: Which Acronis storage tier is designed for long-term archival of rarely accessed backup data at a lower cost?
- Hot storage
- Cloud archive tier (Correct answer)
- Deduplication store
- Primary storage pool
Correct answer: Cloud archive tier
Acronis Cloud archive tier offers lower-cost storage optimized for long-term retention of infrequently accessed backup archives.
Question 3: What is the maximum penalty per violation under GDPR for non-compliance with data protection principles, which could apply if Acronis backups containing personal data are mishandled?
- โฌ20 million or 4% of annual global turnover, whichever is higher (Correct answer)
- โฌ1 million or 1% of annual global turnover
- โฌ5 million or 2% of annual global turnover, whichever is lower
- โฌ10 million or 2% of annual global turnover, whichever is lower
Correct answer: โฌ20 million or 4% of annual global turnover, whichever is higher
GDPR Article 83(5) sets the highest tier of fines at up to โฌ20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious violations.
Question 4: Why stay current with Security & Encryption Protocols trends in Acronis Certified Engineer?
- Not necessary
- Trends irrelevant
- Only for new pros
- Ensures practices remain effective and relevant (Correct answer)
Correct answer: Ensures practices remain effective and relevant
Staying current ensures effective and aligned practices.
Question 5: What does the Acronis End User License Agreement (EULA) typically prohibit regarding license transfers?
- Using the software on virtual machines
- Installing backup agents on servers
- Using the software for disaster recovery purposes
- Transferring licenses to a third party without Acronis written consent (Correct answer)
Correct answer: Transferring licenses to a third party without Acronis written consent
Acronis EULAs generally prohibit sublicensing or transferring licenses to another party without prior written approval from Acronis.
Question 6: Under the California Consumer Privacy Act (CCPA), what right do California residents have regarding their personal data that impacts how Acronis backups must be managed?
- The right to prevent any backup of their personal data
- The right to request deletion of their personal data, requiring processes to locate and purge it from backups (Correct answer)
- The right to demand that all backups be stored in California data centers
- The right to receive an encrypted copy of all backups containing their data
Correct answer: The right to request deletion of their personal data, requiring processes to locate and purge it from backups
CCPA grants California residents the right to request deletion of their personal data, which requires organizations to have processes to identify and delete that data from backup archives.
Question 7: A client wants to ensure their backup data is encrypted both in transit and at rest. What should the ACE configure?
- Use a third-party tool for encryption and leave Acronis settings at default
- Encryption is automatic and cannot be configured by the administrator
- Enable AES-256 encryption in the protection plan and ensure TLS is used for all agent communications (Correct answer)
- Only data at rest can be encrypted; in-transit encryption is not supported
Correct answer: Enable AES-256 encryption in the protection plan and ensure TLS is used for all agent communications
Acronis supports AES-256 encryption for backup archives at rest and uses TLS for all agent-to-server communications in transit.
Question 8: What is the primary purpose of the Acronis Management Server (AMS)?
- Store backups locally
- Handle email notifications only
- Generate PDF compliance reports
- Centrally manage and monitor protection agents (Correct answer)
Correct answer: Centrally manage and monitor protection agents
The Acronis Management Server provides centralized management and monitoring of all protection agents deployed in the environment.
Question 9: What is the significance of FIPS 140-2 compliance in an Acronis deployment for US government environments?
- It enables Acronis to use NSA-approved compression only
- It means Acronis can back up government systems without a license
- It certifies the cryptographic modules meet US federal security standards required for sensitive data (Correct answer)
- It disables all encryption features to comply with export controls
Correct answer: It certifies the cryptographic modules meet US federal security standards required for sensitive data
FIPS 140-2 certification means Acronis's cryptographic modules have been validated to meet US federal standards, which is often mandatory for handling government sensitive data.
Question 10: What is the primary purpose of Acronis Universal Restore?
- To compress backup images for faster bare metal recovery
- To recover a system to dissimilar hardware by injecting appropriate drivers (Correct answer)
- To restore backups directly to cloud object storage
- To synchronize recovery schedules across multiple Acronis agents
Correct answer: To recover a system to dissimilar hardware by injecting appropriate drivers
Acronis Universal Restore enables restoring a system to hardware that differs from the original by detecting and injecting the necessary drivers during the recovery process.
Question 11: When configuring Acronis backup encryption, which encryption mode provides the highest security for CBC vs CTR considerations?
- ECB (Electronic Codebook) mode for its simplicity
- CTR (Counter) mode only, as it is FIPS 140-2 approved
- Acronis always uses ECB regardless of configuration
- CBC (Cipher Block Chaining) which chains blocks for stronger diffusion (Correct answer)
Correct answer: CBC (Cipher Block Chaining) which chains blocks for stronger diffusion
Acronis implements AES in CBC mode, where each cipher block depends on previous blocks, making it more resistant to pattern analysis than ECB mode.
Question 12: A recovery point objective (RPO) of 15 minutes is required for a critical SQL Server. Which Acronis backup configuration best meets this requirement?
- Continuous Data Protection (CDP) with transaction log backup integration (Correct answer)
- Daily full backup with hourly differential backups
- Hourly incremental backups using the 'always incremental' scheme
- 15-minute scheduled full backups of the SQL Server volume
Correct answer: Continuous Data Protection (CDP) with transaction log backup integration
Acronis CDP with SQL Server transaction log integration provides near-continuous protection with recovery points as frequent as every few minutes, easily meeting a 15-minute RPO.
Question 13: Which scenario correctly describes a 'zero-knowledge' encryption model as applied to Acronis backups?
- Acronis staff can decrypt backups for support purposes with special admin credentials
- Encryption keys are split between Acronis and the user using Shamir's Secret Sharing
- Zero-knowledge means no metadata about the backup is transmitted to Acronis servers
- The user holds the only copy of the encryption key, and Acronis has absolutely no ability to decrypt the data (Correct answer)
Correct answer: The user holds the only copy of the encryption key, and Acronis has absolutely no ability to decrypt the data
In zero-knowledge encryption, only the end user possesses the decryption key, making it technically impossible for Acronis to access, decrypt, or hand over backup contents to third parties.
Question 14: What is the primary role of the Acronis Backup Gateway component in Acronis Cyber Infrastructure?
- It orchestrates replication between geographically distributed nodes
- It provides an S3-compatible access layer between backup agents and ACI storage (Correct answer)
- It manages user authentication and license validation
- It encrypts backup data before it reaches the cloud
Correct answer: It provides an S3-compatible access layer between backup agents and ACI storage
Acronis Backup Gateway serves as an S3-compatible API endpoint that connects Acronis backup agents to Acronis Cyber Infrastructure storage pools.
Question 15: What is the importance of Backup Scheduling & Automation in Acronis Certified Engineer?
- It ensures quality, consistency, and professional standards (Correct answer)
- It only matters for large projects
- It is optional
- It is purely aesthetic
Correct answer: It ensures quality, consistency, and professional standards
Backup Scheduling & Automation is essential for maintaining quality, consistency, and meeting professional standards in the field.
Question 16: When documenting a client's backup environment after an Acronis deployment, which information is MOST critical to record?
- The client's preferred email font
- Backup schedules, retention policies, protected workloads, and recovery point objectives (Correct answer)
- The color scheme used in the Acronis console
- The number of monitors on the admin's desk
Correct answer: Backup schedules, retention policies, protected workloads, and recovery point objectives
Documenting schedules, retention policies, workloads, and RPOs ensures continuity and supports future troubleshooting or handovers.
Question 17: Which support option is available for Acronis enterprise users?
- 24/7 technical support (Correct answer)
- Self-guided troubleshooting only
- No official support available
- Community forums only
Correct answer: 24/7 technical support
Acronis enterprise users typically have access to premium support options, including 24/7 technical assistance. This ensures that critical issues affecting business operations can be addressed promptly at any time, minimizing downtime. Such comprehensive support is essential for organizations relying on Acronis for their mission-critical data protection needs.
Question 18: Which Acronis bootable media type provides the broadest hardware compatibility when recovering on modern UEFI systems?
- Linux-based bootable media (Acronis Linux kernel)
- MS-DOS emergency disk
- WinPE-based bootable media (Correct answer)
- ISO-only optical disc media
Correct answer: WinPE-based bootable media
WinPE-based bootable media includes modern Windows drivers and has superior UEFI Secure Boot support, making it the preferred choice for recovering on contemporary hardware.
Question 19: What technical knowledge is essential for Storage Management & Optimization in Acronis Certified Engineer?
- Marketing knowledge only
- Sales techniques only
- Understanding product specifications, compatibility, and integration (Correct answer)
- Basic computer skills only
Correct answer: Understanding product specifications, compatibility, and integration
Storage Management & Optimization requires understanding product specifications, compatibility requirements, and integration possibilities.
Question 20: When an Acronis Management Server certificate expires, what is the immediate operational impact?
- Agents may refuse to communicate with the server and web console HTTPS connections will fail (Correct answer)
- Backup archives are automatically decrypted as a security fallback
- All running backup jobs are immediately terminated
- The server switches to HTTP automatically until a new certificate is installed
Correct answer: Agents may refuse to communicate with the server and web console HTTPS connections will fail
An expired server certificate causes agents and browsers to reject the connection, halting management operations until a valid certificate is installed and trusted.
Question 21: Which method does Acronis use to back up VMware vSphere virtual machines without installing an agent inside each guest VM?
- In-guest agent backup via VMware Tools
- Network-based backup using NBD transport only
- Host-level agentless backup using vSphere APIs (VADP) (Correct answer)
- Storage snapshot integration via SAN
Correct answer: Host-level agentless backup using vSphere APIs (VADP)
Acronis uses VMware vSphere Storage APIs for Data Protection (VADP) to perform agentless backups at the hypervisor level without agents inside guest VMs.
Question 22: Which Acronis recovery option allows an administrator to extract specific files from a full disk-level backup without restoring the entire image?
- Bare metal recovery
- Universal Restore with driver injection
- Granular recovery (Correct answer)
- Instant Restore (Run VM from backup)
Correct answer: Granular recovery
Granular recovery allows administrators to browse a disk-level backup and restore only selected files or folders rather than the entire disk image.
Question 23: After upgrading Acronis Management Server to a new major version, what must also be updated to ensure full compatibility?
- Acronis Agents on all managed machines, as older agents may lack new features (Correct answer)
- Only the web browser on admin workstations to support new console features
- The PostgreSQL database schema only โ agents remain backward-compatible indefinitely
- The Windows Server OS version on the management server host
Correct answer: Acronis Agents on all managed machines, as older agents may lack new features
After a major management server upgrade, agents on managed machines should also be updated to ensure access to new features and full compatibility.
Question 24: When performing bare metal recovery using Acronis bootable media, which protocol is typically used to connect to a remote SMB backup location?
- SFTP with public key authentication only
- SMB/CIFS network share or Acronis agent connection (Correct answer)
- FTP passive mode
- Telnet file transfer
Correct answer: SMB/CIFS network share or Acronis agent connection
Acronis bootable media (both WinPE and Linux) can access remote backup locations via SMB/CIFS network shares or by connecting directly to an Acronis Management Server or Storage Node.
Question 25: Which factor significantly improves backup performance?
- Reduce allocated RAM for Acronis services
- Increase CPU usage limits
- Disable compression on backups
- Use SSD storage for backups (Correct answer)
Correct answer: Use SSD storage for backups
SSDs offer significantly faster read/write speeds compared to traditional HDDs due to their lack of moving parts. This speed advantage allows backup software like Acronis to write data to the backup destination much more quickly. Consequently, using SSD storage for backups directly reduces the time required to complete backup operations, improving overall performance.
Question 26: In Acronis, what does 'backup validation' verify?
- That the backup encryption key is correct
- That the backup data is not corrupted and can be successfully used for recovery (Correct answer)
- That the backup destination has sufficient free space
- That the source machine is compliant with the backup policy
Correct answer: That the backup data is not corrupted and can be successfully used for recovery
Backup validation checks the integrity of backup data by verifying checksums, confirming the archive is intact and recoverable.
Question 27: Which regulatory framework requires healthcare organizations to have a documented Disaster Recovery Plan, which Acronis backup solutions help fulfill?
- GDPR
- CCPA
- PCI DSS
- HIPAA Security Rule (Correct answer)
Correct answer: HIPAA Security Rule
HIPAA's Security Rule (45 CFR ยง164.308) requires covered entities to have a contingency plan including data backup and disaster recovery procedures.
Question 28: In Acronis, when encryption is applied to a backup, where is the encryption password stored?
- In the backup archive metadata
- In the Windows Credential Manager automatically
- It is NOT stored anywhere by Acronis โ the user must remember it (Correct answer)
- In the Acronis management server database
Correct answer: It is NOT stored anywhere by Acronis โ the user must remember it
Acronis does not store encryption passwords; if the password is lost, the backup cannot be recovered, so users must safeguard it independently.
Question 29: In Acronis Cyber Protect, what is the key difference between 'encryption' and 'password protection' on a backup archive?
- They are identical โ both use AES-256 internally
- Password protection only prevents casual access; encryption mathematically scrambles the data making it unreadable without the key (Correct answer)
- Password protection applies during transfer; encryption applies at rest only
- Encryption protects the archive header only; password protection protects all data blocks
Correct answer: Password protection only prevents casual access; encryption mathematically scrambles the data making it unreadable without the key
Password protection can be bypassed with specialized tools if data is unencrypted, while true AES-256 encryption makes the data cryptographically inaccessible without the correct key.
Question 30: Which Acronis Cyber Protect alert indicates that a machine's backup has not been successfully completed within the configured retention period threshold?
- Replication lag alert
- Machine not backed up (Correct answer)
- Backup quota exceeded
- Backup chain corrupted
Correct answer: Machine not backed up
The 'Machine not backed up' alert fires when a machine has gone beyond the configured time limit without a successful backup completion.
Question 31: An Acronis engineer needs to recover a single email from an Exchange database backup without restoring the entire mailbox server. Which recovery method should be used?
- Application-consistent restore
- Bare-metal restore
- Granular recovery for Microsoft Exchange (Correct answer)
- File-level restore
Correct answer: Granular recovery for Microsoft Exchange
Acronis granular recovery for Microsoft Exchange allows extraction of individual emails, folders, or mailboxes directly from a backup without full server restoration.
Question 32: When performing bare metal recovery of a Windows Server Failover Cluster using Acronis, what is the recommended restoration sequence?
- Restore all cluster nodes simultaneously using parallel recovery tasks for speed
- Restore only the active node โ passive nodes automatically rejoin and self-recover
- Restore nodes sequentially with priority given to restoring the quorum disk first (Correct answer)
- Cluster environments require manual data recovery and cannot use Acronis bare metal restore
Correct answer: Restore nodes sequentially with priority given to restoring the quorum disk first
Acronis recommends restoring cluster nodes sequentially, starting with the quorum disk, to ensure cluster membership arbitration is established before other nodes attempt to join.
Question 33: What is a 'synthetic full backup' in Acronis and why is it used?
- A new full backup assembled from existing incremental backups on the storage side without re-reading the source (Correct answer)
- A backup created from a VM snapshot without agent involvement
- A backup that excludes system files to reduce size
- A backup created using agent-side compression only
Correct answer: A new full backup assembled from existing incremental backups on the storage side without re-reading the source
A synthetic full consolidates existing incrementals into a new full backup on the storage side, reducing load on the source machine and network.
Question 34: When setting up Acronis backup to a cloud destination, what does the 'client-side encryption' option mean?
- The cloud provider holds the encryption key for easier recovery
- Data is encrypted on the source machine before leaving for the cloud, so the cloud provider never sees plaintext (Correct answer)
- Encryption is negotiated between the cloud and management server dynamically
- Encryption is applied by the cloud provider after receiving the data
Correct answer: Data is encrypted on the source machine before leaving for the cloud, so the cloud provider never sees plaintext
Client-side encryption ensures data is encrypted locally before upload, meaning even the cloud storage provider cannot access the plaintext contents of the backup.
Question 35: A company requires that all backup encryption keys be centrally managed and rotated quarterly. Which Acronis capability supports this requirement?
- Encryption keys are embedded in each archive and cannot be rotated without full re-backup
- Acronis manages all encryption keys automatically in the management server database
- Integration with external key management systems (KMS) or use of Acronis' built-in key management (Correct answer)
- Only the end-user device can manage its own encryption keys in Acronis
Correct answer: Integration with external key management systems (KMS) or use of Acronis' built-in key management
Acronis supports integration with external KMS solutions and has built-in key management capabilities allowing centralized control and rotation of encryption keys per compliance requirements.
Question 36: In Acronis Cyber Protect, what does Recovery Time Objective (RTO) measure in the context of disaster recovery planning?
- The interval between scheduled backup verification runs
- The maximum acceptable duration to restore a system to operational status after failure (Correct answer)
- The time required to complete a full backup of a protected system
- The maximum amount of data that can be lost measured in time (backup frequency)
Correct answer: The maximum acceptable duration to restore a system to operational status after failure
RTO defines the maximum acceptable time to restore systems and resume business operations after an outage, and bare metal recovery capabilities directly impact achieving RTO goals.
Question 37: An Acronis administrator wants to integrate Acronis Cyber Protect with Microsoft Azure AD for single sign-on. Which configuration section in the web console is used?
- Settings > Security > SAML Configuration (Correct answer)
- Settings > Acronis Agents > Federation
- Settings > Notifications > Identity Providers
- Settings > Users > SSO
Correct answer: Settings > Security > SAML Configuration
SAML-based single sign-on with Azure AD is configured under Settings > Security > SAML Configuration in the Acronis web console.
Question 38: A forensic backup in Acronis Cyber Protect captures which additional data beyond a standard disk backup?
- Network traffic captured during the backup window
- RAM contents and running process information alongside the disk image (Correct answer)
- Active Directory snapshots
- Application logs only
Correct answer: RAM contents and running process information alongside the disk image
Forensic backups in Acronis capture volatile data including RAM contents and running processes, enabling post-incident investigation alongside the disk image.
Question 39: How does Acronis implement bandwidth throttling for backup jobs?
- Through external firewall rules only
- Via network speed limits configured in the backup plan (Correct answer)
- Through DNS traffic shaping
- By modifying TLS cipher settings
Correct answer: Via network speed limits configured in the backup plan
Acronis allows administrators to set network speed limits directly within backup plan settings to control data transfer rates and prevent bandwidth saturation.
Question 40: What cryptographic function does Acronis use to verify backup data integrity after encryption?
- MD5 hash comparison only
- RSA digital signature on the archive header
- SHA-256 cryptographic hash stored in the backup catalog (Correct answer)
- CRC32 checksum embedded in each data block
Correct answer: SHA-256 cryptographic hash stored in the backup catalog
Acronis uses SHA-256 hashing in the backup catalog to create integrity fingerprints, enabling verification that encrypted backup data has not been corrupted or tampered with.
Acronis Certified Engineer (ACE)
The ACE certification validates proficiency in deploying and managing Acronis backup, disaster recovery, security, and cloud solutions. It tests hands-on skills across backup operations, bare metal recovery, encryption, compliance, and audit reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds