malicious and accidental deletions
If you try to delete file name encrypted files via CLI the software simply will not do that, GUI is required to delete such files.
Regarding the rest of your questions:
1) Image-based/VM backups can't be deleted via CLI, so you should be safe here.
2) You can read about our encryption mechanism here
There's too much info to simply copy and paste everything in the thread, so that should actually answer all your questions
3) Not really, and brute-forcing hash is not a smart idea.
Hope that this info helps in making your setup more secure.