ACE Compliance & Licensing Requirements 3 — Questions and Answers
Question 1: Which Acronis product tier is specifically designed for Managed Service Providers (MSPs) and includes multi-tenant licensing management?
- Acronis Cyber Protect Essentials
- Acronis Cyber Protect Cloud (Correct answer)
- Acronis True Image
- Acronis Backup Advanced
Correct answer: Acronis Cyber Protect Cloud
Acronis Cyber Protect Cloud is built for MSPs and includes multi-tenant architecture with per-tenant licensing management through the management portal.
Question 2: Under HIPAA's Security Rule, which Acronis encryption setting best satisfies the requirement to protect ePHI (electronic Protected Health Information) at rest?
- No encryption, relying on physical security of the backup media
- AES-256 encryption applied to backup archives (Correct answer)
- Password protection on the backup destination folder
- MD5 checksums applied to backup files
Correct answer: AES-256 encryption applied to backup archives
HIPAA's Security Rule requires appropriate technical safeguards for ePHI at rest; AES-256 encryption of backup archives meets this requirement.
Question 3: An Acronis partner wants to resell Acronis Cloud services to end customers. Which agreement must they sign with Acronis before doing so?
- Service Level Agreement (SLA)
- Non-Disclosure Agreement (NDA)
- Partner Program Agreement (PPA) or similar reseller agreement (Correct answer)
- Data Processing Agreement (DPA) only
Correct answer: Partner Program Agreement (PPA) or similar reseller agreement
Resellers must execute a Partner Program Agreement with Acronis that grants them the right to market and resell Acronis services to end customers.
Question 4: What is the key distinction between a 'subscription' license and a 'perpetual' license in Acronis products?
- Subscription licenses never expire; perpetual licenses expire annually
- Subscription licenses grant usage rights for a defined period; perpetual licenses grant indefinite usage rights for that version (Correct answer)
- Subscription licenses cover unlimited devices; perpetual licenses are per-device only
- There is no functional difference between the two license types
Correct answer: Subscription licenses grant usage rights for a defined period; perpetual licenses grant indefinite usage rights for that version
A subscription license is time-bound (e.g., 1 or 3 years) while a perpetual license grants the right to use a specific version indefinitely, though both may require active maintenance for updates.
Question 5: Which SOX (Sarbanes-Oxley Act) provision most directly requires that financial data backups be retained and protected with access controls?
- Section 302 — CEO/CFO Certification
- Section 404 — Internal Controls over Financial Reporting
- Section 802 — Criminal Penalties for Altering Documents (Correct answer)
- Section 906 — Corporate Responsibility for Financial Reports
Correct answer: Section 802 — Criminal Penalties for Altering Documents
SOX Section 802 criminalizes the alteration, destruction, or falsification of records, making backup integrity and access controls a legal requirement for financial records.
Question 6: In Acronis Cyber Protect, what does the 'immutable backup' feature provide in the context of compliance?
- Backups that compress data to reduce storage costs
- Backups that cannot be modified or deleted for a defined retention period (Correct answer)
- Backups that automatically replicate to three geographic regions
- Backups that encrypt data using a customer-managed key
Correct answer: Backups that cannot be modified or deleted for a defined retention period
Immutable backups use WORM (Write Once Read Many) technology to prevent alteration or deletion, satisfying compliance requirements like SEC Rule 17a-4 and FINRA.
Question 7: When an Acronis Cyber Protect Cloud customer terminates their service, what is the typical obligation regarding their backup data according to data protection regulations?
- Acronis retains all data indefinitely for legal reasons
- The service provider must delete customer data within a defined period after contract termination (Correct answer)
- Customer data is automatically archived to tape and held for 7 years
- Data is transferred to Acronis headquarters for compliance review
Correct answer: The service provider must delete customer data within a defined period after contract termination
GDPR and similar regulations require that data processors delete personal data after the service relationship ends, typically within 30–90 days as specified in the Data Processing Agreement.
Which Acronis product tier is specifically designed for Managed Service Providers (MSPs) and includes multi-tenant licensing management?