Backup media, rotation and the 3-2-1 rule

Listen to this lesson

Episode 49 · 48:20

Every episode of this course is also a podcast: listen on Spotify.

This episode is a study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.

Objective 4.4 · Troubleshooting · 28% of the exam

Why this matters

The previous lesson covered what goes into each backup. This one covers where backups are kept, for how long, and how many copies exist. Those decisions determine which disasters a backup survives. A perfect backup stored on the same array as the data it protects is lost with it. A backup kept in the server room burns with the server room. A backup reachable with the domain administrator's password is encrypted by the ransomware that stole it.

This lesson covers the media backups are written to, rotation schemes that decide how long each copy is kept, the rule that sets a minimum for how many copies exist and where, encrypting the backups themselves, and keeping all of it in line with the retention policy.

The lesson

Tape, disk, cloud and immutable storage

Backups are written to several kinds of media, each with strengths.

Tape, today almost always LTO (Linear Tape-Open), remains widely used for large-scale backup and archiving. Tape is cheap per terabyte, lasts for decades when stored properly, and, crucially, a tape removed from the library is offline: it cannot be reached over the network at all. Its weaknesses are slow restores of individual files, since tape is read sequentially, and the handling it needs: labelling, transport and storage in suitable conditions. Newer LTO generations also support WORM tapes, which can be written once and never altered.

Disk, whether a backup server's disks, a NAS, or a dedicated backup appliance, is fast for both backup and restore, and supports deduplication, which stores repeated data only once. Its weakness is that it is usually online, and so reachable by anything that compromises the network.

Cloud storage keeps backups at a provider's data centre. It is naturally off site, scales without buying hardware, and is paid for as it is used. Its limits are the internet connection, which makes the first full backup and large restores slow, and the costs, including charges for retrieving data, as the cloud lesson noted. Some providers can ship physical devices to seed or restore large amounts of data.

Immutable storage, covered in the malware lesson, prevents backups being changed or deleted until their retention period ends, even by an administrator. It is available on backup appliances, on disk repositories hardened for the purpose, and in cloud object lock features. Immutability, or an air gap, is what allows backups to survive ransomware.

Most organisations combine media: fast disk for recent backups and quick restores, with copies to tape or cloud for long-term and off-site protection.

Rotation schemes, including grandfather-father-son

A rotation scheme decides which backup media are reused, when, and how long each backup is kept. Without one, backups are either kept forever, using unlimited storage, or overwritten too soon, losing the ability to go back far enough.

The most common is grandfather-father-son (GFS):

  • Son: daily backups, kept for a short period, such as a week, then reused;
  • Father: weekly backups, typically the last backup of each week, kept for a month or so;
  • Grandfather: monthly backups, kept for a year or longer, and often a yearly backup kept longer still.

GFS gives a range of restore points: any day in the last week, any week in the last month, any month in the last year, while keeping the number of backup sets manageable. It answers the common case where a problem, such as a file deleted or corrupted weeks ago, is noticed only long after it happened, when daily backups alone would already have been overwritten.

Other schemes exist, such as the Tower of Hanoi rotation, which uses media on an exponentially spaced schedule, and simple schemes that reuse the same few media each week. Modern backup software usually expresses rotation as retention rules, such as "keep 14 dailies, 8 weeklies and 12 monthlies", applying GFS-style logic automatically.

Whatever the scheme, label and track media carefully, and retire old media: tapes and disks wear out, and a backup is only as good as the media it is on.

The 3-2-1 rule and off-site copies

The 3-2-1 rule is the widely used minimum for backup resilience:

  • 3 copies of the data: the original and at least two backups;
  • on 2 different types of media or storage, so a single fault, such as a firmware bug in one kind of storage, cannot destroy every copy;
  • with 1 copy off site, so a fire, flood or theft at the main site cannot destroy every copy.

A common modern extension is 3-2-1-1-0: add 1 copy that is offline, air-gapped or immutable, to survive ransomware, and 0 errors, confirmed by verifying that backups can actually be restored.

Off-site copies can be tapes taken to a secure storage facility, often by a specialist company that collects and returns them on a schedule; replication to a second data centre; or backups to the cloud. They must be far enough away that a single event cannot affect both sites, such as a regional flood or power failure, and reachable quickly enough to restore within the time the business needs, which the next lesson covers as the recovery time objective.

Transporting and storing off-site media brings in the physical controls from the security domain: locked containers, records of what was sent and received, and a chain of custody, since a lost backup tape is a data breach if it is readable.

Encrypting backups

Backups contain everything: every customer record, every password hash, every confidential document, often going back years. A stolen backup can be worse than a compromised server. Backups also travel and are stored in places, such as courier vans, storage facilities and cloud providers, that the organisation does not fully control.

So backups are encrypted:

  • at rest, on the backup media, using the backup software's encryption, the hardware encryption built into LTO tape drives, or encryption on the storage;
  • in transit, when sent across the network or to the cloud, using TLS or the backup system's own encrypted protocols.

The encryption lesson's warnings apply with extra force. The keys must be managed securely and stored separately from the backups they protect. And they must be available when needed: in a disaster, the backup server and the key management system may themselves have been lost, and a backup whose key is unavailable is as useless as no backup at all. Escrow keys, keep copies in a secure off-site location, document how to retrieve them, and include key recovery in restore tests.

Matching backup retention to the retention policy

Backups are copies of data, and, as the data retention lesson explained, they are subject to the same retention policy as the original.

The rotation scheme is where that policy is enforced for backups:

  • The longest backup retention must meet the longest legal or business requirement for the data it holds. If records must be kept for seven years and can be deleted from live systems sooner, yearly backups or archives must keep them for the full period.
  • Backups must also not be kept longer than the policy allows, especially for personal data that privacy law says should be deleted. Backups kept indefinitely "just in case" defeat that obligation.
  • Legal holds override both: backups containing data covered by a hold must be preserved, and pulled out of rotation, until the hold is released.

Because a single backup usually holds many kinds of data, with different retention periods, organisations often separate backups, kept for recovery over weeks or months, from archives, kept to meet long retention requirements, with their own indexing so specific records can be found. Document the retention for each backup set, and make sure that expired backups are actually destroyed, using the sanitisation methods from the security domain, rather than sitting on a shelf for years.

Practise what you just read

1. What does the 3-2-1 backup rule require?

Select one

  1. Three servers, at two sites, with one tape drive
  2. Three copies, on two media types, with one off site
  3. Three administrators, with two passwords and one key
  4. Three backups a day, kept two weeks, one tested monthly
Show answer

B. Three copies of the data, including the original, on two different types of storage, with one copy off site, so no single failure, fault or site disaster destroys every copy.

2. In grandfather-father-son rotation, what are the 'father' backups?

Select one

  1. The weekly backups
  2. The monthly backups
  3. The daily backups
  4. The yearly backups
Show answer

A. Sons are daily backups kept briefly, fathers are weekly backups kept for about a month, and grandfathers are monthly backups kept for a year or longer.

3. Why is at least one backup copy kept offline or immutable?

Select one

  1. To reduce storage costs by moving older copies to cheaper media
  2. Because offline copies restore faster than copies kept online on disk
  3. Because most regulations name tape as the medium for backup copies
  4. So ransomware and attackers with admin credentials cannot destroy it
Show answer

D. Online backups reachable with stolen credentials can be encrypted or deleted. An air-gapped or immutable copy survives, which is why the extended rule adds one such copy.

7 more questions on this objective are part of the full course.

Practise the full question bank in the exam simulator

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.