Lesson 02 — AWS Backup & Recovery Services
Learning Path
☁️ Phase 02 – AWS Cloud Security
📘 Module 10 – Backup, Disaster Recovery & Business Continuity
🎯 Lesson Objective
Section titled “🎯 Lesson Objective”By the end of this lesson, you will be able to:
- Understand AWS Backup architecture.
- Configure Backup Vaults.
- Create enterprise Backup Plans.
- Configure Backup Rules.
- Implement Backup Lifecycle Policies.
- Perform resource recovery.
- Implement Cross-Account Backups.
- Implement Cross-Region Backups.
- Secure enterprise backups using AWS KMS.
📚 Lesson Information
Estimated Time: 4 Hours
Difficulty: Intermediate
Prerequisites: Lesson 01 – Enterprise Backup Strategy
Hands-on Lab: Yes
💼 Business Scenario
Section titled “💼 Business Scenario”CloudNova Technologies operates critical production workloads across multiple AWS Regions.
Their workloads include:
- 1,500 Amazon EC2 Instances
- 500 Amazon RDS Databases
- 2 PB of Amazon S3 Data
- Amazon EFS File Systems
- Amazon DynamoDB Tables
- Amazon FSx
- VMware workloads
The company currently performs manual backups.
Recent audit findings reveal:
- Missed backups
- Inconsistent retention periods
- Unencrypted snapshots
- No cross-region copies
- No cross-account protection
- No recovery testing
The CIO asks:
“Can we automate backups across every AWS account while ensuring our data remains secure, recoverable and compliant?”
Your task is to design an enterprise backup solution using AWS Backup.
Why AWS Backup?
Section titled “Why AWS Backup?”Managing backups individually becomes difficult as organisations grow.
Without centralised backup management:
- Teams use different schedules.
- Backup retention is inconsistent.
- Recovery becomes complex.
- Compliance reporting is difficult.
AWS Backup centralises backup management across AWS services.
What is AWS Backup?
Section titled “What is AWS Backup?”AWS Backup is a fully managed backup service that centralises data protection across AWS workloads.
It supports:
- Amazon EC2
- Amazon EBS
- Amazon RDS
- Amazon Aurora
- Amazon DynamoDB
- Amazon EFS
- Amazon FSx
- AWS Storage Gateway
- VMware Workloads
- Amazon S3
AWS Backup Architecture
Section titled “AWS Backup Architecture” AWS Organizations │ AWS Backup │ ┌──────────────────┼──────────────────┐ │ │ │ Backup Plan Backup Vault Backup Policies │ │ │ └──────────────────┼──────────────────┘ │ Amazon EC2 / Amazon RDS Amazon EBS / Amazon EFS Amazon S3 / DynamoDB │ Backup Jobs │ Restore JobsAWS Backup Components
Section titled “AWS Backup Components”AWS Backup consists of several key components.
| Component | Purpose |
|---|---|
| Backup Plan | Defines backup schedule |
| Backup Rule | Specifies frequency and retention |
| Backup Vault | Stores recovery points |
| Recovery Point | Backup copy |
| Lifecycle Policy | Controls backup retention |
| Backup Job | Creates backup |
| Restore Job | Restores resource |
Backup Workflow
Section titled “Backup Workflow”Resource
↓
Backup Plan
↓
Backup Rule
↓
Backup Job
↓
Backup Vault
↓
Recovery Point
↓
Restore JobBackup Vault
Section titled “Backup Vault”A Backup Vault securely stores recovery points.
Benefits include:
- Encryption
- Access Control
- Centralised Storage
- Compliance
- Audit Logging
CloudNova creates separate Backup Vaults for:
- Production
- Development
- Disaster Recovery
Backup Vault Encryption
Section titled “Backup Vault Encryption”Every Backup Vault should use AWS KMS encryption.
Backup Vault
↓
AWS KMS Key
↓
Encrypted Recovery Points
↓
Secure StorageBenefits:
- Data confidentiality
- Regulatory compliance
- Secure restores
Backup Plans
Section titled “Backup Plans”Backup Plans define:
- Backup frequency
- Backup window
- Lifecycle
- Retention
- Copy actions
Example:
Production Servers
↓
Daily Backup
↓
30-Day Retention
↓
Weekly Copy
↓
Cross-Region BackupBackup Rules
Section titled “Backup Rules”Each Backup Plan contains one or more Backup Rules.
Example:
| Rule | Schedule |
|---|---|
| Daily | Every Day |
| Weekly | Every Sunday |
| Monthly | First Day of Month |
Multiple rules allow flexible recovery options.
Lifecycle Policies
Section titled “Lifecycle Policies”Lifecycle Policies automatically transition and expire backups.
Example:
Create Backup
↓
30 Days
↓
Cold Storage
↓
365 Days
↓
DeleteBenefits:
- Reduced storage costs
- Compliance
- Automated retention
Backup Windows
Section titled “Backup Windows”Backup Windows specify when backups may start.
Example:
Start Window
02:00 AM
↓
Backup Begins
↓
Completion Window
06:00 AMThis prevents backups from affecting production workloads during peak hours.
Recovery Points
Section titled “Recovery Points”Each successful backup creates a Recovery Point.
Recovery Points contain:
- Snapshot Metadata
- Backup Time
- Encryption Details
- Lifecycle Information
- Restore Information
Resource Assignment
Section titled “Resource Assignment”CloudNova assigns resources using tags.
Example:
Environment=Production
↓
Automatically Assigned
↓
Production Backup PlanThis reduces manual administration.
Cross-Account Backups
Section titled “Cross-Account Backups”Best practice recommends storing backups outside the production account.
Production Account
↓
AWS Backup
↓
Backup Vault
↓
Backup AccountBenefits:
- Protection from ransomware
- Insider threat mitigation
- Better governance
Cross-Region Backups
Section titled “Cross-Region Backups”Regional failures should never result in permanent data loss.
Primary Region
↓
Backup Copy
↓
Secondary Region
↓
Recovery ReadyCritical workloads always have geographically separate backup copies.
Enterprise Backup Architecture
Section titled “Enterprise Backup Architecture” AWS Organizations │ ┌─────────────────┼─────────────────┐ │ │ │ Production Development Backup Account │ │ │ AWS Backup AWS Backup Backup Vault │ │ │ Amazon EC2 Amazon RDS AWS KMS Amazon EBS Amazon EFS Lifecycle Policies Amazon S3 DynamoDB Cross-Region Copies │ Recovery Points │ Restore JobsBackup Monitoring
Section titled “Backup Monitoring”CloudNova continuously monitors:
- Backup Success Rate
- Failed Jobs
- Missed Backups
- Recovery Point Age
- Vault Capacity
- Restore Success Rate
Monitoring ensures backups remain reliable.
Restore Workflow
Section titled “Restore Workflow”Backup Vault
↓
Recovery Point
↓
Restore Job
↓
Validation
↓
Application Testing
↓
Production ReadyRecovery testing is mandatory.
Enterprise Best Practices
Section titled “Enterprise Best Practices”CloudNova standards include:
- Encrypt every Backup Vault.
- Use customer-managed KMS keys.
- Enable Cross-Account Backups.
- Enable Cross-Region Copies.
- Automate Backup Plans.
- Apply Lifecycle Policies.
- Tag resources consistently.
- Test recovery monthly.
- Review backup failures daily.
- Restrict Backup Vault access using IAM.
🛠 Lab 01 — Create a Backup Vault
Section titled “🛠 Lab 01 — Create a Backup Vault”Navigate to:
AWS Console
↓
AWS Backup
↓
Backup Vaults
↓
Create Backup VaultConfigure:
- Name
- AWS KMS Key
- Access Policy
Verify successful creation.
🛠 Lab 02 — Create a Backup Plan
Section titled “🛠 Lab 02 — Create a Backup Plan”Create a Backup Plan for Production EC2.
Configure:
- Daily Backup
- Weekly Backup
- Monthly Backup
- Retention Period
Review the resulting schedule.
🛠 Lab 03 — Assign Resources
Section titled “🛠 Lab 03 — Assign Resources”Assign resources using tags.
Example:
Environment=ProductionVerify automatic resource assignment.
🛠 Lab 04 — Configure Lifecycle Policy
Section titled “🛠 Lab 04 — Configure Lifecycle Policy”Configure:
- Move to Cold Storage
- Retention Period
- Automatic Deletion
Review lifecycle configuration.
🛠 Lab 05 — Configure Cross-Region Backup
Section titled “🛠 Lab 05 — Configure Cross-Region Backup”Create a copy action.
Configure:
- Destination Region
- Backup Vault
- Retention
Verify successful backup copy.
🛠 Lab 06 — Restore an EC2 Instance
Section titled “🛠 Lab 06 — Restore an EC2 Instance”Restore an EC2 instance from a Recovery Point.
Validate:
- Instance Status
- Networking
- Attached Volumes
- Application Functionality
🛠 Lab 07 — Restore an Amazon RDS Database
Section titled “🛠 Lab 07 — Restore an Amazon RDS Database”Restore an RDS database.
Verify:
- Database Availability
- Data Integrity
- Connectivity
- Application Access
💻 AWS CLI Lab
Section titled “💻 AWS CLI Lab”List Backup Vaults
Section titled “List Backup Vaults”aws backup list-backup-vaultsList Backup Plans
Section titled “List Backup Plans”aws backup list-backup-plansList Recovery Points
Section titled “List Recovery Points”aws backup list-recovery-points-by-backup-vault \--backup-vault-name ProductionVaultStart a Backup Job
Section titled “Start a Backup Job”aws backup start-backup-job \--backup-vault-name ProductionVault \--resource-arn RESOURCE_ARN \--iam-role-arn ROLE_ARNList Backup Jobs
Section titled “List Backup Jobs”aws backup list-backup-jobsList Restore Jobs
Section titled “List Restore Jobs”aws backup list-restore-jobsDescribe Backup Vault
Section titled “Describe Backup Vault”aws backup describe-backup-vault \--backup-vault-name ProductionVault✅ Verification
Section titled “✅ Verification”Verify that you can:
✔ Explain AWS Backup architecture.
✔ Create Backup Vaults.
✔ Configure Backup Plans.
✔ Apply Lifecycle Policies.
✔ Assign resources automatically.
✔ Configure Cross-Account Backups.
✔ Configure Cross-Region Backups.
✔ Restore enterprise workloads.
🔍 Troubleshooting
Section titled “🔍 Troubleshooting”Problem
Section titled “Problem”Backup Job failed.
Verify:
- IAM Role permissions.
- Backup Vault configuration.
- Resource availability.
- Backup service permissions.
Problem
Section titled “Problem”Restore failed.
Check:
- Recovery Point exists.
- KMS permissions.
- Target Region.
- Restore IAM Role.
Problem
Section titled “Problem”Resources are not being backed up.
Review:
- Resource Tags.
- Backup Plan Assignment.
- Backup Rule Schedule.
- Backup Windows.
🚫 Common Mistakes
Section titled “🚫 Common Mistakes”❌ Storing backups only in the production account.
❌ Using the default AWS managed KMS key for highly sensitive workloads when customer-managed keys are required by policy.
❌ Never testing recovery.
❌ Applying identical retention policies to every workload.
❌ Forgetting Cross-Region copies.
❌ Ignoring failed backup jobs.
❌ Not protecting Backup Vault access.
🧪 DIY Challenge
Section titled “🧪 DIY Challenge”CloudNova plans to implement an enterprise backup solution for all production workloads.
Design a solution that:
- Protects EC2, RDS, EBS, EFS, DynamoDB and S3.
- Encrypts every Backup Vault.
- Creates daily, weekly and monthly backup schedules.
- Implements Cross-Account Backup.
- Implements Cross-Region Backup.
- Uses Lifecycle Policies for long-term retention.
- Automates resource assignment using tags.
- Includes monthly recovery testing.
Prepare:
- Enterprise Backup Architecture
- Backup Plan Design
- Backup Policy
- Recovery Strategy
- Backup Lifecycle Diagram
- Executive Backup Dashboard
📊 Knowledge Check
Section titled “📊 Knowledge Check”- What is AWS Backup?
- What is the purpose of a Backup Vault?
- What is a Backup Plan?
- What is a Backup Rule?
- Why are Lifecycle Policies important?
- What is a Recovery Point?
- Why should organisations implement Cross-Account Backups?
- Why are Cross-Region Backups recommended for critical workloads?
- Why should Backup Vaults use AWS KMS encryption?
- Why must backup restoration be tested regularly?
💡 Key Takeaways
Section titled “💡 Key Takeaways”After completing this lesson, you should understand:
- AWS Backup centralises backup management across multiple AWS services using Backup Plans, Backup Vaults and automated scheduling.
- Backup Vaults should be encrypted with AWS KMS and protected with appropriate IAM policies to safeguard recovery data.
- Cross-Account and Cross-Region backups improve resilience against ransomware, accidental deletion and regional outages.
- Lifecycle Policies help balance compliance requirements with storage cost optimisation by automatically transitioning and expiring backups.
- A successful backup strategy is only complete when recovery procedures are tested regularly and restore operations are validated.
🚀 Next Lesson
Section titled “🚀 Next Lesson”➡️ Lesson 03 — Disaster Recovery Architectures