13.4 Lifecycle, Backup & Secure Replication Beyond S3: EFS, FSx, DLM, DataSync & Air-Gapped Vaults
Key Takeaways
EFS lifecycle policies transition files into Infrequent Access (console default 30 days), into Archive (default 90 days), and back to Standard on first access.
FSx for Lustre persistent file systems support automatic daily backups retained 0–90 days; scratch and S3-linked file systems can't be backed up.
Amazon Data Lifecycle Manager automates EBS snapshots and EBS-backed AMIs, including cross-Region copies and archiving; AWS Backup covers many services centrally.
Logically air-gapped vaults lock recovery points in compliance mode and can be shared through AWS RAM so a separate account can restore after a compromise.
AWS DataSync encrypts transfers with TLS, verifies data integrity, and can run through a VPC interface endpoint over Direct Connect or VPN.
13.4 Lifecycle, Backup & Secure Replication Beyond S3: EFS, FSx, DLM, DataSync & Air-Gapped Vaults
Skills 5.2.3 and 5.2.4 extend data lifecycle and backup design beyond Amazon S3. The exam guide names Amazon EFS lifecycle policies, Amazon FSx for Lustre backup policies, Amazon Data Lifecycle Manager, AWS Backup, ransomware protection, and AWS DataSync. Questions usually combine retention requirements, cost, and resilience against attackers who have gained administrative access.
Amazon EFS Lifecycle Management
EFS lifecycle policies move files between storage classes based on when they were last accessed:
| Policy | Common Setting | Effect |
|---|---|---|
| Transition into Infrequent Access (IA) | 30 days since last access (the console default) | Moves cold files to lower-cost IA storage |
| Transition into Archive | 90 days since last access (the console default) | Moves rarely read files to the lowest-cost class; requires Elastic throughput |
| Transition into Standard | On first access | Moves a file back to Standard when it is read again |
Security-relevant EFS settings sit alongside lifecycle: encryption at rest must be chosen when the file system is created, a file system policy can deny aws:SecureTransport false to require TLS mounts, and access points enforce a POSIX user and root directory for each application. EFS replication keeps a read-only replica in another Region or Availability Zone for disaster recovery, and new file systems created in the console have automatic backups turned on through AWS Backup.
Amazon FSx for Lustre Backups
FSx for Lustre is often used for high-performance workloads that process data from S3.
- Automatic daily backups are available for persistent file systems, with a retention period of 0–90 days; 0 turns automatic backups off.
- User-initiated backups are kept until you delete them.
- Backups are not supported for scratch file systems or for file systems linked to an S3 data repository, so for those the source data in S3 must be protected instead.
- AWS Backup can manage FSx backups alongside other resources, including copies to other Regions and accounts.
Amazon Data Lifecycle Manager (DLM)
DLM automates EBS snapshots and EBS-backed AMIs using tag-targeted policies: schedules, count- or age-based retention, cross-Region copies (re-encrypted with a destination KMS key), cross-account sharing, fast snapshot restore, and moving older snapshots to the lower-cost archive tier. Choose DLM when requirements are EBS-specific; choose AWS Backup when one policy must cover many services.
AWS Backup for Centralized, Tamper-Resistant Backups
AWS Backup applies backup plans (schedule, lifecycle to cold storage, retention, and copy actions) to resources selected by tag or ID across EBS, EC2, RDS, Aurora, DynamoDB, EFS, FSx, S3, and more.
- Backup vaults encrypt recovery points; for services that AWS Backup fully manages, the vault's KMS key encrypts the backup independently of the source.
- Organization backup policies push plans to member accounts, and cross-account copy within the organization moves recovery points to a separate backup account.
- AWS Backup Vault Lock in compliance mode makes recovery points immutable after the grace period (Section 13.3).
- Legal holds keep specific recovery points beyond their normal retention for litigation or investigations.
- Restore testing restores recovery points on a schedule and validates them, proving recoverability.
- AWS Backup Audit Manager evaluates backup activity against frameworks (for example, "resources are protected by a backup plan with minimum retention") and produces reports.
Logically Air-Gapped Vaults
A logically air-gapped vault is a special vault type for ransomware recovery. Its recovery points are locked in compliance mode, so they can't be deleted before retention ends, and the vault can be shared through AWS RAM with other accounts, even accounts outside the organization, which can restore directly from it. If the owning account is compromised, a recovery account can still restore, and multi-party approval can provide a trusted team with access when normal credentials are lost.
Ransomware-Resilient Backup Architecture
| Control | Purpose |
|---|---|
| Dedicated backup account in a separate OU | Attackers in workload accounts can't reach backup copies |
| Cross-account and cross-Region copies | Survive account compromise and Regional events |
| Vault Lock (compliance mode) or logically air-gapped vault | Prevent deletion or shortened retention, even by root |
| SCPs denying backup deletion and policy changes in workload accounts | Stop tampering with local backup settings |
| Customer managed KMS keys in the backup account | Keep decryption under the backup team's control |
| Restore testing and Backup Audit Manager | Prove backups exist and can be restored |
AWS DataSync for Secure Transfer and Replication
DataSync moves data between on-premises storage (NFS, SMB, HDFS, object storage), other clouds, and AWS storage services (S3, EFS, and FSx).
- Encryption in transit: All data is encrypted with TLS between the DataSync agent (or source) and AWS.
- Integrity verification: Tasks can verify only the data transferred, verify all data at the destination, or skip verification; checksums confirm that what arrived matches the source.
- Private connectivity: Agents can activate with and send data through a VPC interface endpoint for DataSync, keeping transfers on Direct Connect or VPN.
- Least privilege: DataSync assumes an IAM role you provide to write to S3 destinations; scope it to the target bucket and prefix.
- Auditability: Task reports and CloudWatch Logs record which files transferred, were skipped, or failed verification.
Specialty Exam Pitfalls
- Expecting backups for FSx for Lustre scratch file systems: Scratch and S3-linked file systems don't support backups; protect the S3 data instead.
- Backups in the same account as the workload: An attacker with administrator access can delete them. Copy to an isolated account and lock the vault.
- Choosing DLM for multi-service requirements: DLM covers EBS snapshots and AMIs only.
- Confusing lifecycle with retention locks: EFS and S3 lifecycle policies change storage class or expire data; they don't prevent deletion. Use Vault Lock or Object Lock for immutability.
A research team stores project files on Amazon EFS. Most files are read heavily for two weeks and then rarely, but some are reopened unpredictably months later. The team wants to minimize storage cost automatically while keeping reopened files fast to access. Which configuration meets these requirements?
Enable EFS lifecycle management with transition into IA after 30 days, transition into Archive after 90 days, and transition into Standard on first access.
Create an S3 Lifecycle rule for the EFS file system.
Use Amazon Data Lifecycle Manager to snapshot the file system and delete old files.
Enable EFS replication to another Region and delete the source files after 30 days.
A company runs an FSx for Lustre scratch file system linked to an S3 data repository for a genomics pipeline. The compliance team asks the storage engineer to enable daily automatic backups of the file system with 30-day retention. What should the engineer explain?
Automatic backups are enabled by default with 90-day retention on all FSx for Lustre file systems.
Backups must be taken with Amazon Data Lifecycle Manager.
The file system must be converted to EFS before it can be backed up.
Backups aren't supported for scratch file systems or file systems linked to an S3 data repository, so protect the source data in S3 (for example, with versioning, replication, or AWS Backup for S3); persistent file systems support daily automatic backups with 0–90 days of retention.
After a ransomware incident in another company, a CISO requires that backups remain recoverable even if an attacker gains administrator or root access to the production account, and that a separate recovery account be able to restore data without first copying it back. Which design best meets these requirements?
Enable AWS Backup in the production account with a daily backup plan and a 35-day retention period.
Copy recovery points to a logically air-gapped vault in an isolated backup account, and share the vault through AWS RAM with the recovery account.
Take EBS snapshots with DLM and share them publicly so they can be restored anywhere.
Use S3 Lifecycle rules to move backups to S3 Glacier Deep Archive in the production account.
A company migrates 200 TB from an on-premises NFS server to Amazon EFS over AWS Direct Connect. Security requires that data never traverse the public internet, that transfers be encrypted, and that the destination be checked against the source. Which approach meets these requirements?
Mount EFS on premises over a public virtual interface and copy files with rsync.
Upload files to a public S3 bucket and then copy them to EFS.
Deploy an AWS DataSync agent on premises that activates and transfers through a DataSync VPC interface endpoint, with task verification enabled.
Use AWS Snowball Edge and skip data integrity checks to save time.
Sections you finish are checked off in the contents.