Skip to content

Runbook 01 Build Enterprise Backup, Disaster Recovery & Business Continuity Solution

Module: 10 – Backup, Disaster Recovery & Business Continuity

Enterprise Lab: 01

Estimated Time: 5–6 Hours

Difficulty: ⭐⭐⭐⭐☆

Estimated Cost: AWS Backup, AWS Elastic Disaster Recovery (DRS), Cross-Region Replication, and backup storage may incur charges. Review AWS Pricing and monitor AWS Cost Explorer throughout this lab.


As a Cloud Security Engineer at CloudNova Technologies, your responsibility is to design and implement an enterprise-grade backup and disaster recovery solution that protects critical workloads from accidental deletion, ransomware attacks, hardware failures, and regional outages.

By completing this runbook, you will learn how to:

  • Configure AWS Backup
  • Create Backup Vaults
  • Create Backup Plans
  • Configure Backup Policies
  • Protect Amazon EC2
  • Protect Amazon EBS
  • Protect Amazon RDS
  • Enable Amazon S3 Versioning
  • Configure Amazon S3 Cross-Region Replication
  • Configure AWS Elastic Disaster Recovery (DRS)
  • Configure Backup Encryption
  • Validate Backups
  • Restore Resources
  • Perform Disaster Recovery Testing
  • Validate Recovery Point Objective (RPO)
  • Validate Recovery Time Objective (RTO)

CloudNova Technologies hosts multiple customer-facing business applications in AWS.

Following several high-profile ransomware attacks across the industry, executive management has requested a complete backup and disaster recovery strategy to ensure business continuity.

The environment must be capable of recovering from:

  • Accidental resource deletion
  • Ransomware attacks
  • Data corruption
  • Availability Zone failures
  • Regional disasters
  • Infrastructure failures

As the Cloud Security Engineer, you are responsible for implementing and validating the recovery solution before production deployment.


Complete:

  • Module 01 – AWS Security Foundations
  • Module 02 – Identity & Access Management
  • Module 03 – AWS Organizations & Multi-Account Security
  • Module 04 – Amazon VPC & Network Security
  • Module 05 – Amazon EC2 Security
  • Module 06 – Data Protection & Encryption
  • Module 07 – Logging, Monitoring & Threat Detection
  • Module 08 – Network Protection
  • Module 09 – Vulnerability & Compliance Management

Required:

  • AWS Account
  • Administrator Access
  • Existing EC2 Instance
  • Existing Amazon RDS Database
  • Existing Amazon S3 Bucket
  • AWS CLI Installed
  • Visual Studio Code

CloudNova AWS Production
EC2 Amazon RDS Amazon S3
│ │ │
└──────┬───────┴──────────────┘
AWS Backup
Backup Vault
Encrypted Recovery Points
Cross-Region Backup Copy
AWS Elastic Disaster Recovery
Disaster Recovery Region
Recovery Testing Environment

Navigate to:

AWS Console
AWS Backup
Getting Started

Enable AWS Backup.

Review:

  • Backup Vaults
  • Backup Plans
  • Protected Resources

Terminal window
aws backup list-backup-vaults

Validate:

  • AWS Backup Enabled
  • Backup Service Operational

Navigate to:

AWS Backup
Backup Vaults
Create Backup Vault

Configuration

Vault Name
CloudNova-Production-Vault
Encryption
AWS KMS Customer Managed Key

Validate:

  • Vault Created
  • Encryption Enabled

Navigate to:

AWS Backup
Backup Plans
Create Backup Plan

Configure:

  • Daily Backup
  • Weekly Backup
  • Monthly Backup
  • Annual Backup

Retention Example

Daily
30 Days
Weekly
12 Weeks
Monthly
12 Months

Discuss:

  • Retention Policies
  • Compliance Requirements
  • Backup Scheduling

Assign EC2 instances to the Backup Plan.

Validate:

  • EC2 Protected
  • Recovery Points Created

Review:

  • Backup Jobs
  • Recovery Points

Review attached EBS volumes.

Ensure:

  • Automated Snapshots
  • Encryption Enabled
  • Backup Retention Configured

Terminal window
aws ec2 describe-snapshots --owner-ids self

Navigate to:

Amazon RDS
Databases
Backups

Verify:

  • Automated Backups Enabled
  • Backup Retention
  • Point-in-Time Recovery

Review:

  • Snapshot Schedule
  • Recovery Window

Navigate to:

Amazon S3
Bucket
Properties

Enable:

  • Versioning

Discuss:

  • Accidental Deletion
  • Ransomware Recovery
  • Object Recovery

Terminal window
aws s3api get-bucket-versioning \
--bucket YOUR_BUCKET_NAME

Step 8 — Configure Cross-Region Replication

Section titled “Step 8 — Configure Cross-Region Replication”

Configure:

  • Destination Region
  • IAM Replication Role
  • Replication Rules

Validate:

  • Objects Replicated
  • Replication Status

Discuss:

  • Regional Disaster Recovery
  • High Availability

Step 9 — Configure AWS Elastic Disaster Recovery (DRS)

Section titled “Step 9 — Configure AWS Elastic Disaster Recovery (DRS)”

Navigate to:

AWS Elastic Disaster Recovery

Configure:

  • Source Servers
  • Replication Settings
  • Staging Area
  • Recovery Servers

Validate:

  • Replication Healthy
  • Recovery Ready

Discuss:

  • Pilot Light
  • Warm Standby
  • Active/Passive Recovery

Review:

  • Backup Vault Encryption
  • Snapshot Encryption
  • RDS Encryption
  • S3 Encryption
  • KMS Keys

Questions:

  • Are all backups encrypted?
  • Are customer-managed keys used where appropriate?

Review:

  • Backup Jobs
  • Recovery Points
  • Backup Success Rate
  • Backup Failures

Ensure:

  • No failed backup jobs
  • Recovery Points available
  • Backup schedules operating correctly

Restore:

  • EC2 Instance
  • EBS Volume
  • Amazon RDS Database
  • Amazon S3 Object

Validate:

  • Successful Recovery
  • Application Starts
  • Data Integrity Maintained

Step 13 — Validate Disaster Recovery Objectives

Section titled “Step 13 — Validate Disaster Recovery Objectives”

Measure:

Recovery Point Objective (RPO)

Target
≤ 15 Minutes

Recovery Time Objective (RTO)

Target
≤ 60 Minutes

Document:

  • Actual Recovery Time
  • Data Loss
  • Recovery Challenges

CloudNova Technologies has suffered a ransomware attack affecting its production AWS environment.

The attack resulted in:

  • Critical EC2 instances encrypted
  • Production RDS database corrupted
  • Important files deleted from Amazon S3
  • Regional outage impacting primary workloads

As the Cloud Security Engineer, you must:

  • Recover EC2 instances
  • Restore the RDS database
  • Recover deleted S3 objects
  • Validate backup integrity
  • Activate Disaster Recovery procedures
  • Measure actual RPO and RTO
  • Document the recovery process
  • Present an executive recovery report to the CISO

Capture screenshots of:

  • AWS Backup Dashboard
  • Backup Vault
  • Backup Plan
  • Recovery Points
  • EBS Snapshots
  • Amazon RDS Backup
  • Amazon S3 Versioning
  • Cross-Region Replication
  • AWS Elastic Disaster Recovery
  • Restored Resources

Submit:

  • Backup Architecture Diagram
  • Disaster Recovery Architecture
  • Business Continuity Plan
  • Recovery Test Report
  • RPO/RTO Results
  • Executive Summary

Delete:

  • Test EC2 Recovery Instances
  • Test EBS Volumes
  • Test Recovery Resources
  • Temporary Recovery Servers
  • Test Snapshots (if no longer required)

Keep:

  • Backup Vault
  • Backup Plans
  • Production Recovery Points
  • Disaster Recovery Documentation
  • Business Continuity Procedures

Review AWS Cost Explorer to ensure no unnecessary recovery resources remain active.


  • AWS Backup Configured
  • Backup Vault Created
  • Backup Plan Created
  • EC2 Protected
  • EBS Snapshots Verified
  • RDS Backups Verified
  • S3 Versioning Enabled
  • Cross-Region Replication Configured
  • AWS Elastic Disaster Recovery Configured
  • Backup Encryption Validated
  • Recovery Test Completed
  • RPO/RTO Measured
  • Disaster Recovery Documentation Completed

Why should backup recovery be tested regularly instead of assuming backups will work?

Section titled “Why should backup recovery be tested regularly instead of assuming backups will work?”

How do AWS Backup, Amazon S3 Versioning, and AWS Elastic Disaster Recovery work together to improve resilience?

Section titled “How do AWS Backup, Amazon S3 Versioning, and AWS Elastic Disaster Recovery work together to improve resilience?”

Why are RPO and RTO critical metrics when designing enterprise disaster recovery solutions?

Section titled “Why are RPO and RTO critical metrics when designing enterprise disaster recovery solutions?”

How would you improve CloudNova Technologies’ backup and disaster recovery strategy for a multi-region AWS environment?

Section titled “How would you improve CloudNova Technologies’ backup and disaster recovery strategy for a multi-region AWS environment?”

Enterprise Runbook 02 — Enterprise Backup & Disaster Recovery Assessment

In the next runbook, you will assess an enterprise AWS backup and disaster recovery implementation by reviewing backup configurations, recovery points, backup encryption, disaster recovery readiness, recovery testing, business continuity documentation, and resilience controls to produce a comprehensive executive disaster recovery assessment report.