Security & Encryption Protocols Flashcards
7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Encryption Protocols flashcards as text
An Acronis administrator suspects a man-in-the-middle attack on agent communications. Which action best mitigates this risk?
Answer: Replace self-signed certificates with CA-signed certificates and enable certificate pinning
CA-signed certificates with pinning prevent MITM attacks by ensuring agents only accept certificates from a trusted authority that matches an expected fingerprint.
In Acronis Cyber Protect, what is the key difference between 'encryption' and 'password protection' on a backup archive?
Answer: Password protection only prevents casual access; encryption mathematically scrambles the data making it unreadable without the key
Password protection can be bypassed with specialized tools if data is unencrypted, while true AES-256 encryption makes the data cryptographically inaccessible without the correct key.
Which Acronis feature uses behavioral analysis to detect ransomware attempting to encrypt files that are being backed up?
Answer: Active Protection with AI-based heuristics
Acronis Active Protection uses AI-driven behavioral analysis to detect ransomware-like encryption patterns in real time and can block the attack and recover affected files from cache.
When setting up Acronis backup to a cloud destination, what does the 'client-side encryption' option mean?
Answer: Data is encrypted on the source machine before leaving for the cloud, so the cloud provider never sees plaintext
Client-side encryption ensures data is encrypted locally before upload, meaning even the cloud storage provider cannot access the plaintext contents of the backup.
A company requires that all backup encryption keys be centrally managed and rotated quarterly. Which Acronis capability supports this requirement?
Answer: Integration with external key management systems (KMS) or use of Acronis' built-in key management
Acronis supports integration with external KMS solutions and has built-in key management capabilities allowing centralized control and rotation of encryption keys per compliance requirements.
What cryptographic function does Acronis use to verify backup data integrity after encryption?
Answer: SHA-256 cryptographic hash stored in the backup catalog
Acronis uses SHA-256 hashing in the backup catalog to create integrity fingerprints, enabling verification that encrypted backup data has not been corrupted or tampered with.
In Acronis Cyber Protect Cloud, what is the purpose of tenant isolation in a multi-tenant security architecture?
Answer: To cryptographically separate each customer's data and management plane so tenants cannot access each other's resources
Tenant isolation in Acronis Cloud uses cryptographic separation and access controls to ensure each customer's backup data and management operations are completely isolated from other tenants.