← All ACE Flashcard Decks

Compliance & Licensing Requirements Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance & Licensing Requirements flashcards as text
  1. What is the maximum penalty per violation under GDPR for non-compliance with data protection principles, which could apply if Acronis backups containing personal data are mishandled?

    Answer: €20 million or 4% of annual global turnover, whichever is higher

    GDPR Article 83(5) sets the highest tier of fines at up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious violations.

  2. Which Acronis feature allows administrators to define different retention policies for different data classifications to meet varying compliance requirements?

    Answer: Backup Plan Templates with custom retention rules per plan

    Backup Plan Templates in Acronis allow administrators to create separate plans with distinct retention schedules, enabling different data classes to meet their specific regulatory retention requirements.

  3. Under the California Consumer Privacy Act (CCPA), what right do California residents have regarding their personal data that impacts how Acronis backups must be managed?

    Answer: The right to request deletion of their personal data, requiring processes to locate and purge it from backups

    CCPA grants California residents the right to request deletion of their personal data, which requires organizations to have processes to identify and delete that data from backup archives.

  4. What does Acronis's SOC 2 Type II certification demonstrate to customers?

    Answer: That Acronis's internal controls for security, availability, and confidentiality have been independently audited over a period of time

    SOC 2 Type II certification means an independent auditor has verified that Acronis's operational controls for Trust Services Criteria were effective over an observation period, typically 6-12 months.

  5. An organization needs to comply with a regulation requiring all backup data to remain within US borders. Which Acronis deployment option best satisfies this data residency requirement?

    Answer: On-premises Acronis Cyber Infrastructure deployed in a US facility, or Acronis Cloud with US-only data center selection

    Data residency requirements mandate that data never leaves a specified geographic boundary; on-premises deployment or cloud with explicit US data center selection ensures this compliance.

  6. When an Acronis license includes 'Advanced Security' add-on, what additional compliance benefit does the EDR (Endpoint Detection and Response) component provide?

    Answer: Audit trails and forensic data collection that support regulatory incident reporting requirements

    EDR capabilities in Acronis Advanced Security generate forensic audit trails and attack timelines that support mandatory incident reporting under regulations like GDPR's 72-hour breach notification rule.

  7. In Acronis Cyber Protect Cloud, which role-based access control (RBAC) configuration best supports the compliance principle of 'least privilege'?

    Answer: Granting users only the specific roles needed for their job function, such as Backup Operator or Viewer

    Least privilege requires each user to have only the minimum permissions necessary for their role; Acronis's granular RBAC roles like Backup Operator or Viewer implement this principle.