3.1.3.2. Backup & Recovery Strategies (Pilot Light, Warm Standby)
3.1.3.2. Backup & Recovery Strategies (Pilot Light, Warm Standby)
Backup & Restore implementation:
- AWS Backup creates scheduled backups of RDS, EBS, EFS, DynamoDB
- Cross-region backup copies stored in S3 in the DR region
- On disaster: restore resources from backups, deploy infrastructure via CloudFormation, update DNS
- RTO: Hours (depends on data size and infrastructure complexity)
Pilot Light implementation:
- RDS read replica or Aurora Global Database running in DR region
- S3 cross-region replication active
- AMIs copied to DR region
- CloudFormation templates ready to deploy compute layer
- On disaster: promote DB replica, launch EC2/ECS from templates, update Route 53
Warm Standby implementation:
- Full application stack running in DR region at reduced capacity (e.g., 1 instance instead of 10)
- Database synchronously or asynchronously replicated
- Route 53 health checks configured for automatic failover
- On disaster: scale up DR environment (ASG adjusts capacity), traffic shifts automatically
AWS Backup centralizes backup management across services:
# Create a backup plan with cross-region copy
aws backup create-backup-plan --backup-plan '{
"BackupPlanName": "DailyDR",
"Rules": [{
"RuleName": "DailyBackup",
"ScheduleExpression": "cron(0 2 * * ? *)",
"TargetBackupVaultName": "primary-vault",
"CopyActions": [{
"DestinationBackupVaultArn": "arn:aws:backup:us-west-2:123456789012:backup-vault:dr-vault"
}]
}]
}'
Exam Trap: AWS Backup supports cross-account backups (copy to backup vault in another account). This protects against account compromise — even if an attacker gains admin access to the primary account, backups in the security account are safe. The exam tests this pattern in security-focused DR questions.
Backup Vault Lock: in compliance mode, once the grace time ends the lock can't be removed, and no user — including the root user — nor AWS can delete recovery points early or shorten retention; governance mode can be removed by users with sufficient IAM permissions. IAM policies and SCPs can be edited by administrators, so they don't give this guarantee.
Point-in-time recovery (PITR): RDS automated backups (and AWS Backup continuous backup for RDS) let you restore to any second within the retention period, up to the latest restorable time (typically within the last 5 minutes) — the tool for an accidental DROP TABLE between daily snapshots. The restore creates a new DB instance.