Asterrr's Handbook

Backup and ransomware protection

AWS Backup plans and org backup policies, Vault Lock modes, logically air-gapped vaults, cross-account and cross-Region copies, Data Lifecycle Manager, secure transfer with DataSync, integrity checks and restore testing.

Exam tasks: 5.2.2 (integrity: code signing, file validation), 5.2.3 (retention: FSx for Lustre and other backups), 5.2.4 (secure replication and backup: DLM, AWS Backup, ransomware protection, DataSync)

The decision: if an attacker gets administrator access to a production account (or the whole account is closed), which copy of your data survives, who can restore it, and how do you know the copy is intact?

A ransomware-resistant layout

  • Backups that live in the same account as production can be deleted by whoever compromises that account. Copy them to an account the workload administrators can't touch.
  • Lock the destination vault so even that account's administrators can't shorten retention.
  • Guard the backup account with SCPs that deny backup:DeleteBackupVault, backup:DeleteRecoveryPoint, backup:PutBackupVaultLockConfiguration changes and kms:ScheduleKeyDeletion on backup keys, except for a break-glass role.

AWS Backup building blocks

PieceWhat it does
Backup planRules with a schedule, backup window, lifecycle (warm to cold storage), retention and copy actions to another Region or account
Resource assignmentSelects resources by tag, ARN or type, so new resources tagged backup=gold are covered automatically
Backup vaultContainer for recovery points, with its own KMS key and an access policy (for example, deny DeleteRecoveryPoint to everyone)
Organization backup policyDefined in the management account or a delegated administrator, attached to OUs; deploys plans to every member account and stops local admins editing them
Backup Audit ManagerFrameworks of controls ("resources are in a plan", "backups are copied cross-Region", "vault is locked") with reports
Legal holdKeeps selected recovery points past their retention until the hold is released

Encryption of backups

  • For resource types fully managed by AWS Backup (for example EFS, DynamoDB with advanced features, S3), the recovery point is encrypted with the vault's KMS key.
  • For other types (EBS snapshots, RDS snapshots), the backup keeps the source resource's key. That's why an RDS database encrypted with aws/rds can't be copied to another account: its key can't be shared. Use a customer managed key on the source.
  • Cross-account copies need the destination vault's key policy and the source key policy to allow the other account, and both accounts must be in the same organization.

Vault Lock and air-gapped vaults

Vault Lock governanceVault Lock complianceLogically air-gapped vault
Who can remove the lockIAM principals with permissionNobody after the grace time, not even AWSNobody; compliance lock is built in
Grace timeNoneAt least 72 hoursNot applicable
Retention boundsOptional min and maxOptional min (1 day or more) and maxRequired: min 7 days or more, and a max
EncryptionVault keyVault keyAWS owned key by default, or a customer managed key
Restore from another accountCopy back firstCopy back firstYes, share with AWS RAM or recover through multi-party approval
Use forGuardrails while you tune retentionWORM retention for regulators (SEC 17a-4, FINRA)Fast recovery when the owning account is compromised or closed
  • Backups in a locked vault can't be deleted early by anyone, including the root user.
  • Once a compliance lock passes its grace time, the vault can be deleted only when it's empty, so check retention values carefully; a mistake keeps costing money until the recovery points expire.
  • Multi-party approval lets a team of approvers authorise restoring from a logically air-gapped vault into another account even when the owning account is inaccessible.

Exam signal

"Protect backups from a compromised administrator" means cross-account copies to a vault with Vault Lock in compliance mode. "Restore quickly into a new account without copying first, even if the source account is gone" means a logically air-gapped vault shared through RAM or unlocked through multi-party approval.

Two different vault locks

AWS Backup Vault Lock protects recovery points in backup vaults. Glacier Vault Lock was a policy lock on the original Glacier vault service, which no longer takes new customers. S3 Object Lock protects object versions in buckets. Match the lock to the storage the question describes.

Amazon Data Lifecycle Manager

  • Automates creation, retention (by count or age), cross-Region copy and cross-account sharing of EBS snapshots and EBS-backed AMIs, at no extra charge. Also supports fast snapshot restore and moving snapshots to the archive tier.
  • Default policies give every instance or volume in a Region a baseline snapshot schedule without tagging.
  • Cross-account copy event policies in a target account automatically copy snapshots shared with it, re-encrypted with the target account's key.
  • DLM only manages snapshots it created. For more than EC2 and EBS, central reporting, Vault Lock or org-wide policies, use AWS Backup.
NeedDLMAWS Backup
EBS snapshot and AMI schedules onlyYesYes
RDS, DynamoDB, EFS, FSx, S3 and moreNoYes
Immutable (locked) retentionNoYes
Organization-wide policies and audit reportsNoYes
Application-consistent pre and post scripts on EC2Yes, through SSM documentsYes (VSS for Windows)

Retention on file and storage services

  • FSx for Lustre backs up only persistent file systems not linked to S3. Automatic daily backups keep 0–90 days (0 turns them off, and it's the default); user-initiated backups never expire. Use AWS Backup for longer retention, hourly schedules and cross-Region copies.
  • EFS automatic backups through AWS Backup are on by default for new file systems created in the console.
  • RDS automated backups keep up to 35 days; for longer or immutable retention, use AWS Backup.

Secure replication and transfer

  • S3 Replication (same- or cross-Region): versioning on both buckets; for SSE-KMS objects, opt in and grant the replication role Decrypt on the source key and Encrypt on the destination key. Use owner override so the destination account owns replicas, and consider not replicating delete markers so a malicious delete in the source doesn't propagate.
  • AWS DataSync encrypts in transit with TLS, and can run through an interface VPC endpoint so transfers from on-premises stay on your Direct Connect or VPN. It writes with the destination's default encryption.
  • DataSync verifies checksums during every transfer. Choose Verify only transferred data (recommended), Verify all data, or no final check.

Proving integrity

NeedControl
CloudTrail logs weren't altered or deletedLog file integrity validation: hourly signed digest files with SHA-256 hashes; validate with aws cloudtrail validate-logs
Objects weren't corrupted on upload or copyS3 checksums (CRC64NVME by default, or SHA-256 you supply), checked on upload and stored with the object
Transfer copied data faithfullyDataSync verification modes
Lambda runs only code your team signedAWS Signer signing profile plus a Lambda code signing configuration set to Enforce
Container images weren't tampered withSign images with AWS Signer (Notation) and verify at deploy time
Backups can actually be restoredRestore testing in AWS Backup: scheduled restores of selected recovery points, optional validation with Lambda, automatic clean-up
72 hours
Minimum grace time before a compliance-mode Backup Vault Lock becomes immutable.
7 days
Minimum retention on a logically air-gapped vault.
0–90 days
Retention range for FSx for Lustre automatic daily backups.
35 days
Longest RDS automated backup retention.

Scenarios

Scenario
A ransomware group gained administrator access to a retailer's production account and deleted RDS snapshots and EBS snapshots stored there. The retailer wants to ensure this can't happen again, and that backups can't be deleted even by administrators of the account that stores them. Which solution meets these requirements?
Scenario
A backup administrator's cross-account copy job fails for an Amazon RDS for MySQL database, while EFS copies to the same destination vault succeed. The database is encrypted with the aws/rds key. What should the administrator do?
Scenario
An audit committee asks for evidence that the company's nightly backups of critical EC2 instances and Aurora clusters can be restored, with the least manual effort. What should the security engineer set up?

Further reading

On this page