| | |

LFCA 67 ๐Ÿง Backup Concepts โ€” Full, Incremental, Differential

A backup strategy is not a single tool or a single command. It is a plan that answers three questions: what to back up, how often, and how to restore it. The three fundamental backup types โ€” full, incremental, and differential โ€” are the building blocks of that plan. Each one trades storage space, backup time, and restore complexity in a different way.

The LFCA exam places backup and recovery under System Administration Fundamentals, which carries 20% of the total weight . The competency list explicitly includes “Implement backup strategies” and “Disaster Recovery” with recovery planning . Knowing the definitions is not enough. The exam tests whether you understand the trade-offs โ€” why you would choose one type over another, and what happens when you need to restore.

Key point: A full backup copies everything, every time. A differential backup copies everything that changed since the last full backup. An incremental backup copies everything that changed since the last backup of any type . The difference between differential and incremental is what each one references: the full backup, or the most recent backup. That single distinction determines how many files you need to restore.


Why backup types exist

A backup strategy is a compromise between three competing concerns: how much space the backups consume, how long the backup takes to run, and how long the restore takes when you need it. No single type optimizes all three.

The storage problem. A full backup copies every file every time. For a system with 500 GB of data, that is 500 GB per backup. Run it daily for a week, and you have 3.5 TB of backups. Incremental backups copy only the files that changed since the last backup, which might be a few megabytes on a quiet day . The difference in storage requirements is the primary reason incremental backups exist.

The backup window problem. A full backup of a large system takes hours. If it runs during the day, it competes with users for disk I/O and network bandwidth. Incremental backups take minutes because they copy so little. This allows more frequent backups โ€” hourly instead of nightly โ€” without disrupting the system.

The restore problem. This is the hidden cost of incremental backups. A full backup restores in one step: copy everything. A differential backup restores in two steps: copy the full backup, then copy the most recent differential. An incremental backup restores in N steps: copy the full backup, then every incremental backup in order, from oldest to newest . If you have a weekly full backup and daily incrementals, restoring from Friday requires the full backup plus five incremental files. If any one of those files is corrupted, the restore fails.

The trade-off. Full backups are simple to restore but expensive to store. Incremental backups are cheap to store but complex to restore. Differential backups sit in the middle: they are larger than incremental backups (because each differential grows as more changes accumulate since the last full backup), but restoring requires only two files instead of many . Most production systems combine all three: a periodic full backup, supplemented by differential and incremental backups .


a. Full Backups

A full backup copies the entire dataset โ€” every file, every directory, every configuration โ€” regardless of whether it has changed since the last backup . It is the foundation of every backup strategy. Without a full backup, neither differential nor incremental backups have a reference point.

# A full backup with tar
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc /var/www

# A full backup with rsync
rsync -aAXv --delete / /backup/full-system/ \
  --exclude={/dev/*,/proc/*,/sys/*,/tmp/*,/run/*,/mnt/*}

The tar command creates a compressed archive of the specified directories. The -c flag creates the archive, -z compresses it with gzip, -p preserves permissions, and -f specifies the output file . The $(date +%F) substitution appends the current date to the filename, so each full backup is separate. The rsync command synchronizes the entire filesystem to a backup directory, excluding pseudo-filesystems that should not be backed up .

The advantage of a full backup is simplicity. The restore is a single command: extract the archive or synchronize the backup directory back to the source. There is no dependency chain, no “restore the full, then restore these six incrementals in order.” One file, one restore .

The disadvantage is cost. Every full backup contains the same data. If the dataset is 100 GB and you run full backups weekly, you consume 100 GB of storage every week for data that has barely changed. For systems with large datasets and slow change rates, this is wasteful.


b. Differential Backups

A differential backup copies everything that has changed since the last full backup . The key word is “full.” A differential backup does not care about other differential backups. It only compares the current state to the state at the time of the last full backup.

# A differential backup with tar (using GNU tar's --newer flag)
tar -czpf /backup/diff-$(date +%F).tar.gz \
  --newer="$(cat /backup/last-full-date)" \
  /home /etc /var/www

The --newer flag tells tar to include only files modified after the timestamp stored in /backup/last-full-date. The timestamp file is updated when a full backup runs. This produces a differential backup: everything changed since that date.

The behavior of a differential backup over time is important. On Monday, after a Sunday full backup, the differential contains Monday’s changes. On Tuesday, the differential contains Monday’s and Tuesday’s changes. On Wednesday, it contains Monday’s, Tuesday’s, and Wednesday’s. The differential grows larger each day because it accumulates every change since the full backup .

This growth is the distinguishing characteristic of differential backups. They start small and get progressively larger. An incremental backup, by contrast, stays roughly the same size every day because it only references the previous backup, not the full one.

The restore process for a differential backup requires two files: the last full backup and the most recent differential . You do not need the differentials from Monday, Tuesday, and Wednesday โ€” only the most recent one, because it contains all the changes since the full backup. This is the advantage of differential over incremental: fewer files to restore, less chance of a corrupted link in the chain.


c. Incremental Backups

An incremental backup copies everything that has changed since the last backup of any type โ€” whether that was a full backup, a differential backup, or another incremental backup . This is the critical distinction. Differential backups reference the full backup. Incremental backups reference whatever backup ran most recently.

# An incremental backup with rsync
rsync -aAXv --link-dest=/backup/previous/ /home /backup/current/

# The --link-dest flag creates hard links to unchanged files,
# so only changed files consume new space.

The rsync command with --link-dest is the classic incremental backup technique. Unchanged files are hard-linked to the previous backup, so they do not consume additional space. Only files that have changed are copied as new data . The result is a directory that looks like a full backup but shares most of its data with the previous backup.

The size behavior of incremental backups is flat. Monday’s incremental contains Monday’s changes. Tuesday’s contains Tuesday’s changes. Wednesday’s contains Wednesday’s changes. Each one is roughly the same size, assuming the daily change rate is constant. Unlike differential backups, which grow, incremental backups stay small .

The restore process is the cost. To restore from incremental backups, you must restore the last full backup, then every incremental backup in sequence, from oldest to newest . If you have a weekly full backup and daily incrementals, restoring from Friday requires the full backup plus five incremental files. Each one must be applied in order. If the third incremental is corrupted, the restore stops there, and you lose everything after that point.

The xfsrestore command illustrates this cumulative restore process for XFS filesystems. The -r option “cumulatively restore[s] all data starting from a level 0 backup and working through all available incremental backups” . The command must be run multiple times, once for the full backup and once for each incremental, in order.


Complete Example Session

This session demonstrates the three backup types using tar and rsync, then walks through the restore process for each.

# ============================================
# PART 1: THE FULL BACKUP
# ============================================

# Create a full backup of /home and /etc
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc

# Record the timestamp for differential backups
date +%F > /backup/last-full-date

# Verify the backup
tar tzf /backup/full-2025-05-07.tar.gz | head -20

# ============================================
# PART 2: THE DIFFERENTIAL BACKUP
# ============================================

# Two days later, a file is modified
echo "new config" >> /etc/myapp.conf

# Create a differential backup (changes since the full backup)
tar -czpf /backup/diff-$(date +%F).tar.gz \
  --newer="$(cat /backup/last-full-date)" \
  /home /etc

# The differential contains myapp.conf but not unchanged files.

# ============================================
# PART 3: THE INCREMENTAL BACKUP WITH RSYNC
# ============================================

# First full backup
rsync -aAXv /home/ /backup/rsync/full/

# Next day: incremental backup with hard links
rsync -aAXv --link-dest=/backup/rsync/full/ \
  /home/ /backup/rsync/inc-2025-05-08/

# Next day: another incremental, linking to the previous one
rsync -aAXv --link-dest=/backup/rsync/inc-2025-05-08/ \
  /home/ /backup/rsync/inc-2025-05-09/

# Unchanged files are hard links. Only new files consume space.

# ============================================
# PART 4: RESTORING FROM A FULL BACKUP
# ============================================

# One command, everything restored
mkdir -p /tmp/restore-full
tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-full

# ============================================
# PART 5: RESTORING FROM A DIFFERENTIAL BACKUP
# ============================================

# Step 1: restore the full backup
mkdir -p /tmp/restore-diff
tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-diff

# Step 2: restore the most recent differential
tar -xzpf /backup/diff-2025-05-09.tar.gz -C /tmp/restore-diff

# Two files. The differential contains all changes since the full.

# ============================================
# PART 6: RESTORING FROM INCREMENTAL BACKUPS
# ============================================

# Step 1: restore the full backup
mkdir -p /tmp/restore-inc
rsync -aAXv /backup/rsync/full/ /tmp/restore-inc/

# Step 2: restore each incremental in order
rsync -aAXv /backup/rsync/inc-2025-05-08/ /tmp/restore-inc/
rsync -aAXv /backup/rsync/inc-2025-05-09/ /tmp/restore-inc/

# Every file in the chain must be present and uncorrupted.

# ============================================
# PART 7: THE SIZE COMPARISON
# ============================================

# Full backups: same size every time
du -sh /backup/full-*.tar.gz
# 100M  full-2025-05-07.tar.gz

# Differential backups: grow over time
du -sh /backup/diff-*.tar.gz
# 5M   diff-2025-05-08.tar.gz   (Monday changes)
# 12M  diff-2025-05-09.tar.gz   (Monday + Tuesday changes)

# Incremental backups: roughly constant
du -sh /backup/rsync/inc-*/ | tail -3
# 5M   inc-2025-05-08/
# 5M   inc-2025-05-09/

# ============================================
# PART 8: THE RESTORE TIME COMPARISON
# ============================================

# Full: 1 file, fastest
time tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-full

# Differential: 2 files, moderate
time (tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-diff && \
      tar -xzpf /backup/diff-2025-05-09.tar.gz -C /tmp/restore-diff)

# Incremental: N files, slowest
time (rsync -aAXv /backup/rsync/full/ /tmp/restore-inc/ && \
      rsync -aAXv /backup/rsync/inc-2025-05-08/ /tmp/restore-inc/ && \
      rsync -aAXv /backup/rsync/inc-2025-05-09/ /tmp/restore-inc/)

# ============================================
# PART 9: THE COMBINED STRATEGY
# ============================================

# Weekly full backup on Sunday
0 2 * * 0 tar -czpf /backup/full-$(date +\%F).tar.gz /home /etc

# Daily differential backup Monday through Saturday
0 2 * * 1-6 tar -czpf /backup/diff-$(date +\%F).tar.gz \
  --newer="$(cat /backup/last-full-date)" /home /etc

# This gives the simplicity of differential restore
# with the storage savings of not running full backups daily.

# ============================================
# PART 10: THE BACKUP VERIFICATION
# ============================================

# Verify a tar archive is readable
tar tzf /backup/full-2025-05-07.tar.gz > /dev/null && echo "OK"

# Verify rsync backup is complete
rsync -aAXvn /home/ /backup/rsync/full/ --delete

# The -n flag (dry run) shows what would change.
# No output means the backup is current.

The ten parts cover the full backup, the differential backup, the incremental backup with rsync, restoring from a full backup, restoring from a differential backup, restoring from incremental backups, the size comparison, the restore time comparison, the combined strategy, and backup verification.


Quick Reference

The Three Backup Types

TypeCopiesReferencesRestore Files
FullEverythingNothing1
DifferentialChanges since last fullLast full backup2
IncrementalChanges since last backupMost recent backup1 + N

The Trade-Off Matrix

ConcernFullDifferentialIncremental
Storage per backupLargestModerate, growsSmallest
Backup speedSlowestModerateFastest
Restore speedFastestModerateSlowest
Restore complexityLowestModerateHighest
Files to restore121 + N

The Common Commands

ToolFull BackupIncremental
tartar -czpf archive.tar.gz /pathtar --newer=date
rsyncrsync -aAXv /src/ /dest/rsync --link-dest=prev
dddd if=/dev/sda of=disk.imgNot suited

The Strategy Guidelines

ScenarioRecommended Strategy
Small dataset, fast restoreFull daily
Large dataset, moderate restoreWeekly full + daily differential
Very large dataset, space-constrainedWeekly full + daily incremental
Mission-criticalFull + differential + off-site copies

Best Practices

โœ… Do This:

# Run a full backup before a differential chain starts
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc              # โœ…
# Record the full backup timestamp for differential backups
date +%F > /backup/last-full-date                                  # โœ…
# Use --link-dest for space-efficient incremental backups
rsync -aAXv --link-dest=/backup/previous/ /home /backup/current/  # โœ…
# Test the restore, not just the backup
tar -xzpf /backup/full.tar.gz -C /tmp/restore-test                 # โœ…
# Follow the 3-2-1 rule: 3 copies, 2 media, 1 off-site
# The live system is copy 1. Backups are copies 2 and 3.           # โœ…

โŒ Don’t Do This:

# Don't run only incremental backups forever
# You need a full backup as the foundation.                        # โŒ
# Don't assume a differential backup is small
# It grows every day until the next full backup.                  # โŒ
# Don't skip the full backup in an incremental chain
# The restore will fail without it.                               # โŒ
# Don't store backups on the same disk as the data
# A disk failure destroys both.                                   # โŒ

Common Pitfalls

PitfallWhy It HappensFix
Restore failsMissing an incremental in the chainVerify all files are present
Differential grows too largeFull backup not run often enoughIncrease full backup frequency
Backup takes too longRunning full backup dailySwitch to differential or incremental
Space exhaustedToo many full backups retainedRotate and delete old backups
Corrupted backup unknownNever tested the restoreRestore to a test location periodically

Real-World Examples

1. Full Backup with tar

tar -czpf /backup/full-$(date +%F).tar.gz /home /etc

2. Full Backup with rsync

rsync -aAXv / /backup/full-system/ --exclude={/proc,/sys,/dev}

3. Differential Backup

tar -czpf /backup/diff-$(date +%F).tar.gz --newer="$(cat /backup/last-full-date)" /home

4. Incremental with rsync

rsync -aAXv --link-dest=/backup/previous/ /home /backup/current/

5. Restore Full

tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore

6. Restore Differential

tar -xzpf /backup/full.tar.gz -C /tmp/restore && tar -xzpf /backup/diff.tar.gz -C /tmp/restore

7. Restore Incremental

rsync -aAXv /backup/full/ /tmp/restore/ && rsync -aAXv /backup/inc-1/ /tmp/restore/

8. Verify tar Archive

tar tzf /backup/full.tar.gz > /dev/null && echo "OK"

9. Combined Strategy (cron)

0 2 * * 0 tar -czpf /backup/full-$(date +\%F).tar.gz /home
0 2 * * 1-6 tar -czpf /backup/diff-$(date +\%F).tar.gz --newer="$(cat /backup/last-full-date)" /home

10. 3-2-1 Rule

# 3 copies: live + local backup + off-site backup
# 2 media: disk + tape (or disk + cloud)
# 1 off-site: rsync to remote server
rsync -avz /backup/ user@remote:/backup/

Visual

The Three Backup Types

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  FULL BACKUP                                 โ”‚
โ”‚                                              โ”‚
โ”‚  Sunday:  [=========================] 100M   โ”‚
โ”‚  Monday:  [=========================] 100M   โ”‚
โ”‚  Tuesday: [=========================] 100M   โ”‚
โ”‚                                              โ”‚
โ”‚  Every backup is complete.                   โ”‚
โ”‚  Restore: 1 file.                            โ”‚
โ”‚                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  DIFFERENTIAL BACKUP                         โ”‚
โ”‚                                              โ”‚
โ”‚  Sunday:  [=========================] 100M   โ”‚ (full)
โ”‚  Monday:  [==] 5M                            โ”‚ (since full)
โ”‚  Tuesday: [=====] 12M                        โ”‚ (since full)
โ”‚                                              โ”‚
โ”‚  Each differential references the full.      โ”‚
โ”‚  Restore: full + most recent differential.   โ”‚
โ”‚                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  INCREMENTAL BACKUP                          โ”‚
โ”‚                                              โ”‚
โ”‚  Sunday:  [=========================] 100M   โ”‚ (full)
โ”‚  Monday:  [==] 5M                            โ”‚ (since Sunday)
โ”‚  Tuesday: [==] 5M                            โ”‚ (since Monday)
โ”‚                                              โ”‚
โ”‚  Each incremental references the previous.   โ”‚
โ”‚  Restore: full + every incremental in order. โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The Restore Chain

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  RESTORE FROM FULL                           โ”‚
โ”‚                                              โ”‚
โ”‚  Full โ”€โ”€> Restored. Done.                    โ”‚
โ”‚                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  RESTORE FROM DIFFERENTIAL                   โ”‚
โ”‚                                              โ”‚
โ”‚  Full โ”€โ”€> Differential โ”€โ”€> Restored.         โ”‚
โ”‚                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  RESTORE FROM INCREMENTAL                    โ”‚
โ”‚                                              โ”‚
โ”‚  Full โ”€โ”€> Inc1 โ”€โ”€> Inc2 โ”€โ”€> Inc3 โ”€โ”€> ...     โ”‚
โ”‚                                              โ”‚
โ”‚  Every file must be present.                 โ”‚
โ”‚  Every file must be uncorrupted.             โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The Size Over Time

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  SIZE OVER TIME                              โ”‚
โ”‚                                              โ”‚
โ”‚  Full:        constant (large)               โ”‚
โ”‚  โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€               โ”‚
โ”‚  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ          โ”‚
โ”‚  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ          โ”‚
โ”‚                                              โ”‚
โ”‚  Differential: grows (moderate)              โ”‚
โ”‚  โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€               โ”‚
โ”‚  โ–ˆโ–ˆ                                          โ”‚
โ”‚  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ                                    โ”‚
โ”‚  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ                              โ”‚
โ”‚                                              โ”‚
โ”‚  Incremental: constant (small)               โ”‚
โ”‚  โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€               โ”‚
โ”‚  โ–ˆโ–ˆ                                          โ”‚
โ”‚  โ–ˆโ–ˆ                                          โ”‚
โ”‚  โ–ˆโ–ˆ                                          โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The 3-2-1 Rule

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  THE 3-2-1 RULE                              โ”‚
โ”‚                                              โ”‚
โ”‚  3 copies:                                   โ”‚
โ”‚    1. Live system                            โ”‚
โ”‚    2. Local backup                           โ”‚
โ”‚    3. Off-site backup                        โ”‚
โ”‚                                              โ”‚
โ”‚  2 different media:                          โ”‚
โ”‚    e.g., disk + tape, or disk + cloud        โ”‚
โ”‚                                              โ”‚
โ”‚  1 off-site:                                 โ”‚
โ”‚    Protects against fire, theft, ransomware  โ”‚
โ”‚                                              โ”‚
โ”‚  The live system is not a backup.            โ”‚
โ”‚  It is the source.                           โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Summary

ItemValue
Full backupEverything, every time
Differential backupChanges since last full backup
Incremental backupChanges since last backup of any type
Full restore1 file
Differential restore2 files (full + most recent diff)
Incremental restore1 + N files (full + all incrementals)
Differential sizeGrows over time
Incremental sizeConstant
Common tooltar for archives, rsync for synchronization
rsync incremental--link-dest for hard-linked unchanged files
Best practice3-2-1: 3 copies, 2 media, 1 off-site

Key takeaways:

  • Full backups copy everything; differential and incremental backups copy only what changed. The distinction between differential and incremental is what they reference: differential references the last full backup, incremental references the last backup of any type .
  • Differential backups grow over time; incremental backups stay roughly constant. A differential on Monday contains one day of changes. On Tuesday, it contains two days. On Wednesday, three. An incremental always contains one day (or one backup period) of changes .
  • Restore complexity is the hidden cost of incremental backups. A full backup restores in one step. A differential restores in two. An incremental restores in N steps, where N is the number of incremental backups since the last full backup. Every file in the chain must be present and uncorrupted .
  • Most production systems use a combination. A weekly full backup provides the foundation. Daily differential or incremental backups capture changes. The choice between differential and incremental depends on whether you prioritize restore simplicity or storage efficiency .
  • tar and rsync are the standard Linux backup tools. tar creates compressed archives suitable for full and differential backups. rsync with --link-dest creates space-efficient incremental backups using hard links to unchanged files .
  • The 3-2-1 rule is the industry standard for backup strategy. Keep three copies of your data, on two different types of media, with at least one copy off-site. The live system is not a backup โ€” it is the source. Backups are the additional copies .
  • Always test the restore, not just the backup. A backup that cannot be restored is not a backup. Restore to a test location periodically to verify that the process works and the data is intact .

Remember: Full, differential, and incremental backups are not competing strategies. They are building blocks. A full backup is the foundation. Differential backups sit on top of it, capturing everything since the last full. Incremental backups capture everything since the last backup of any kind. The choice between them is a trade-off between storage space, backup time, and restore complexity. Full backups are simple to restore but expensive to store. Incremental backups are cheap to store but complex to restore. Differential backups sit in the middle. The 3-2-1 rule ensures that no single failure destroys all copies. And the only backup that matters is the one you have tested restoring.


Stop using slow, ad-bloated tool sites! ๐Ÿคฎ

๐Ÿ”Ž Search “KandZ Tools” on Google to use many professional utilities for free.

KandZ.me is the ultimate minimalist hub for:
โœ… Finance (Mortgage, Interest, Inflation)
โœ… Tech (Base64, JSON, Dev Suite, IP)
โœ… Health (BMI, BMR, TDEE)
โœ… Productivity (Timer, Workspace, QR)

โšก๏ธ Fast & Private
๐Ÿ”’ No data leaves your device
๐Ÿ’Ž 100% Free

๐Ÿ”— Use it now: https://tools.kandz.me
๐Ÿ”– Bookmark itโ€”youโ€™ll need it later!