Security & Encryption Protocols Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Encryption Protocols flashcards as text
Which scenario correctly describes a 'zero-knowledge' encryption model as applied to Acronis backups?
Answer: The user holds the only copy of the encryption key, and Acronis has absolutely no ability to decrypt the data
In zero-knowledge encryption, only the end user possesses the decryption key, making it technically impossible for Acronis to access, decrypt, or hand over backup contents to third parties.
An Acronis backup plan uses AES-256 encryption with a password. A brute-force attack is attempted on the archive. Approximately how many possible AES-256 key combinations exist?
Answer: 2^256 (approximately 1.16 × 10^77)
AES-256 has a keyspace of 2^256 possible combinations, making brute-force attacks computationally infeasible with any foreseeable technology.
When an Acronis Management Server certificate expires, what is the immediate operational impact?
Answer: Agents may refuse to communicate with the server and web console HTTPS connections will fail
An expired server certificate causes agents and browsers to reject the connection, halting management operations until a valid certificate is installed and trusted.
Which Acronis security protocol prevents a backup agent from being spoofed by a rogue server on the same network segment?
Answer: Certificate pinning — agents validate the management server certificate fingerprint against a stored expected value
Certificate pinning ensures that even if a rogue server presents a valid-looking certificate, the agent rejects it unless the fingerprint matches the pinned expected value from initial trusted registration.
In Acronis Cyber Protect, what is the recommended approach for backing up encryption keys themselves to prevent loss?
Answer: Maintain a separate secure, offline record of encryption passwords independent of the Acronis system
Encryption passwords must be stored separately from the backups they protect — a secure offline record (such as a password manager or printed secure storage) is the recommended approach.
What is the security implication of enabling deduplication alongside encryption in Acronis backups?
Answer: Encryption must be disabled for deduplication to function, as deduplication requires comparing plaintext data blocks
Standard encryption produces unique ciphertext even from identical plaintext, so deduplication cannot match encrypted blocks — deduplication must occur before encryption or encryption must be disabled for dedup to work.
A healthcare organization using Acronis Cyber Protect must comply with HIPAA's security rule. Which encryption configuration best satisfies HIPAA requirements for backup data?
Answer: AES-256 encryption with individual access-controlled keys and documented key management procedures
HIPAA requires appropriate technical safeguards for ePHI; AES-256 with access-controlled keys and documented key management procedures satisfies encryption addressable specifications and audit trail requirements.