Storage
Backup, archival and data protection
Data recovery, retention and protection are explicit parts of Domain 1 (task 1.3) and Domain 4 (task 4.1). The goal is to back up the right data, keep it for the right time, store it at the right price, and be able to restore it — even after ransomware or an account compromise.
AWS Backup
A central, policy-based backup service for many AWS services:
- Supported resources include EC2/EBS, RDS, Aurora, DynamoDB, EFS, FSx, S3, Storage Gateway volumes, DocumentDB, Neptune and more.
- Backup plans — schedules, retention periods, lifecycle to cold storage, and copy rules to other Regions or accounts.
- Backup vaults — where recovery points are stored, encrypted with KMS.
- AWS Backup Vault Lock — makes backups immutable (WORM); in compliance mode, not even the root user can delete them before retention ends.
- Cross-account backups via AWS Organizations — protect against compromise of a production account.
- Backup Audit Manager — reports on compliance with backup policies.
Key idea
"Centrally manage backups for many services and accounts with retention policies" → AWS Backup. "Backups must be immutable" → Vault Lock (and/or S3 Object Lock).
Service-native backups
| Service | Mechanism |
|---|---|
| EBS | Snapshots (incremental), Data Lifecycle Manager |
| RDS | Automated backups (retention up to 35 days, point-in-time restore) + manual snapshots (kept until deleted) |
| Aurora | Continuous backups, point-in-time restore, snapshots, backtrack (MySQL-compatible) |
| DynamoDB | Point-in-time recovery (up to 35 days), on-demand backups, export to S3 |
| S3 | Versioning, replication, Object Lock |
| EFS / FSx | AWS Backup, FSx automatic backups |
Designing a backup strategy
- Classify data — what's critical, regulated, re-creatable.
- Set RPO — how much data loss is acceptable → backup frequency (snapshot every hour vs day).
- Set RTO — how quickly you must recover → restore method and DR strategy (see resilient design).
- Set retention — legal and business requirements (e.g. 7 years).
- Protect backups — separate account, cross-Region copy, encryption, immutability.
- Test restores regularly.
Archival on S3 Glacier
| Need | Storage class |
|---|---|
| Archive, instant access a few times a year | Glacier Instant Retrieval |
| Archive, retrieval in minutes to hours is fine | Glacier Flexible Retrieval |
| Long-term archive at the lowest cost, retrieval within 12–48 hours | Glacier Deep Archive |
S3 Glacier also supports vaults with Vault Lock policies (the original Glacier API) for compliance controls.
Data retention and classification
- Tag data by classification (public, internal, confidential, regulated) to drive policies.
- Use lifecycle rules to delete data when retention ends (privacy laws often require deletion as well as retention).
- Use Macie to find sensitive data, and Object Lock legal holds for litigation.
Exam patterns
- "Back up EC2, RDS and DynamoDB in all accounts daily and keep 90 days, copy to another Region" → AWS Backup plan with copy rule (organization-wide).
- "Ransomware must not be able to delete backups" → Vault Lock in compliance mode, cross-account backup vault.
- "Keep audit data 10 years at the lowest cost, retrieval within two days is fine" → Glacier Deep Archive.
- "Restore a database to its state at 10:42 yesterday" → point-in-time recovery.