LFCA 120 ๐ง Real-World Scenario โ Setting Up a Backup
A backup that has never been restored is not a backup. It is a hope. This chapter walks through setting up a backup system on a Linux host, but it treats the restore as the point, not an afterthought. You will create archives with tar, synchronize file trees with rsync, schedule automated runs, andโcriticallyโverify that the backup can actually be used to recover data. The LFCA exam tests backup as part of the operations domain, and the skill it evaluates is not the ability to run a command but the judgment to know what to back up, where to store it, and how to prove it works .
This chapter covers the three primary native tools: tar for compressed archives, rsync for efficient file synchronization, and dd for disk imaging. You will see how each tool fits into a backup strategy, when to choose one over another, and how to combine them. The scenario is a typical server deployment: a web server with application data, configuration files, and user content that needs protection against hardware failure, accidental deletion, and configuration errors.
Key point: A backup strategy is not defined by the tool you use. It is defined by the answers to four questions: what data needs protecting, how often it changes, where the backup will be stored, and how you will verify it can be restored.
Why backup strategy matters
The data loss problem. Hardware fails. Disks develop bad sectors. Filesystems corrupt. Users delete files they meant to keep. Configuration changes break services. A backup is the only protection against these events. But a backup that exists only on the same disk as the original data is not protection; it is a copy waiting to be lost alongside the original. The first principle of backup is geographic separation: the backup must live somewhere the original data does not.
The restore problem. Most backup failures are discovered during restore, when it is too late. An archive that was never tested may be corrupt. A rsync mirror that has been running for months with --delete may have faithfully replicated a deletion that should never have propagated. The only way to know a backup works is to restore from it. This chapter treats the restore drill as mandatory, not optional .
The scope problem. What should be backed up? A full system backup includes the operating system, installed packages, configuration files, and user data. But it also includes pseudo-filesystems like /proc, /sys, and /dev that contain no real data and should never be archived. Backing up the wrong directories wastes space and time. Backing up too little means the restore is incomplete. The scope of a backup is a decision, not a default.
The frequency problem. Data changes at different rates. A database transaction log changes every second. A configuration file changes when an administrator edits it. A user’s documents change when they work on them. A single backup schedule cannot serve all of these needs efficiently. The strategy must match the frequency to the data’s rate of change.
The LFCA domain coverage. The LFCA exam includes operations and disaster recovery as a tested domain . Backup and restore are the concrete skills in that domain. The exam expects candidates to know the tools (tar, rsync, dd), the automation methods (cron, systemd timers), and the verification techniques that confirm a backup is usable.
a. Creating archives with tar
The tar command creates archivesโsingle files that contain multiple files and directories. It is the most universal backup tool on Linux, installed on every distribution, with no dependencies beyond the base system . The tar command preserves file permissions, ownership, and timestamps when used correctly.
# Create a compressed archive of /etc
sudo tar -czvpf /backup/etc-backup-$(date +%Y%m%d).tar.gz /etc
# Create a compressed archive of multiple directories
sudo tar -czvpf /backup/system-backup-$(date +%Y%m%d).tar.gz \
/etc /home /var/www /opt/app
The flags are: -c for create, -z for gzip compression, -v for verbose output, -p for preserving permissions, and -f for specifying the filename. The -p flag is critical for system backups; without it, ownership and permission information may not be preserved in the archive .
For full system backups, certain directories must be excluded. The /proc, /sys, /dev, /run, and /tmp directories are virtual or temporary filesystems. They contain no persistent data, and backing them up can cause errors or produce useless archives .
# Full system backup with exclusions
sudo tar -czvpf /backup/full-backup-$(date +%Y%m%d).tar.gz \
--exclude='/proc' \
--exclude='/sys' \
--exclude='/dev' \
--exclude='/run' \
--exclude='/tmp' \
--exclude='/mnt' \
--exclude='/media' \
--exclude='/lost+found' \
/
The tar command also supports verification. After creating an archive, you can list its contents without extracting to confirm the archive is readable and contains the expected files.
# Verify archive integrity by listing contents
tar -tzf /backup/etc-backup-20261006.tar.gz > /dev/null && echo "Archive OK"
If the archive is corrupt or truncated, tar returns an error. This is a basic but essential check before relying on the backup .
b. Synchronizing with rsync
The rsync command synchronizes files between two locations. Unlike tar, which creates a single archive, rsync maintains a file tree at the destination that mirrors the source. This makes individual file restoration trivialโyou simply copy the file back .
The basic rsync command for backup uses archive mode and the --delete flag.
# Local backup with rsync
rsync -avh --delete /home/user/ /backup/home/user/
The flags are: -a for archive mode (preserves permissions, timestamps, symlinks, and recursion), -v for verbose, -h for human-readable sizes, and --delete to remove files from the destination that no longer exist in the source. The --delete flag is what makes rsync a mirror rather than an accumulator; without it, deleted files linger in the backup forever .
The trailing slash on the source path matters. rsync -av /home/user/ /backup/ copies the contents of /home/user into /backup. rsync -av /home/user /backup/ copies the directory itself, creating /backup/user. Always use the trailing slash when you want to copy contents .
For remote backups, rsync can transfer over SSH.
# Remote backup over SSH with compression
rsync -avz -e ssh /home/user/ backup-user@backup-server:/backups/user/
The -z flag enables compression during transfer, which reduces bandwidth usage. The -e ssh specifies SSH as the remote shell .
A critical safety practice with rsync --delete is to run a dry run first. The -n or --dry-run flag shows what would be transferred or deleted without making any changes.
# Dry run to preview changes
rsync -avhn --delete /home/user/ /backup/home/user/
If the dry run output looks correct, remove the -n flag to execute the backup. This prevents the catastrophic scenario of --delete removing files from the destination that should have been preserved .
c. Automating and verifying backups
Manual backups are backups that will eventually be forgotten. Automation is not optional for a reliable strategy. The two standard scheduling tools on Linux are cron and systemd timers.
cron is the traditional method. A cron job is a line in a crontab file that specifies a command and a schedule.
# Edit the root crontab
sudo crontab -e
# Add a daily backup at 2:00 AM
0 2 * * * /usr/local/bin/backup.sh >> /var/log/backup.log 2>&1
The five fields represent minute, hour, day of month, month, and day of week. The 0 2 * * * schedule means 2:00 AM every day. The >> /var/log/backup.log 2>&1 redirects both standard output and standard error to a log file .
A limitation of cron is that it does not run missed jobs. If the system is powered off at 2:00 AM, the backup does not happen when the system comes back up. systemd timers address this with the Persistent=true directive, which runs a missed job as soon as the system is available .
A systemd timer requires two files: a service unit that defines what to run, and a timer unit that defines when to run it.
# /etc/systemd/system/backup.service
[Unit]
Description=Daily backup
[Service]
Type=oneshot
ExecStart=/usr/local/bin/backup.sh
# /etc/systemd/system/backup.timer
[Unit]
Description=Run daily backup
[Timer]
OnCalendar=*-*-* 02:00:00
Persistent=true
[Install]
WantedBy=timers.target
After creating the files, reload systemd and enable the timer.
sudo systemctl daemon-reload
sudo systemctl enable --now backup.timer
systemctl list-timers backup.timer
The systemd timer approach is recommended on modern systems because it integrates with the journal for logging, handles missed runs, and uses the same management commands as other services .
The final and most important step is verification. A backup script should include a check that the archive was created successfully and is not empty.
# Verify the backup archive
if tar -tzf "$ARCHIVE" > /dev/null 2>&1; then
echo "$(date): Backup verified: $ARCHIVE"
else
echo "$(date): BACKUP FAILED: $ARCHIVE" >&2
exit 1
fi
But archive integrity is not the same as restorability. The only true verification is a restore drill. Periodically extract the backup to a temporary directory and confirm that the files are present and readable.
# Restore drill: extract to a test directory
mkdir -p /tmp/restore-test
tar -xzf /backup/etc-backup-20261006.tar.gz -C /tmp/restore-test
ls -la /tmp/restore-test/etc/
This test takes seconds and confirms that the backup is not just an archive but a usable recovery point .
Complete Example Session
# ============================================
# PART 1: CREATE BACKUP DIRECTORY
# ============================================
sudo mkdir -p /backup
sudo chmod 700 /backup
# ============================================
# PART 2: FULL SYSTEM ARCHIVE WITH TAR
# ============================================
sudo tar -czvpf /backup/full-$(date +%Y%m%d).tar.gz \
--exclude='/proc' --exclude='/sys' --exclude='/dev' \
--exclude='/run' --exclude='/tmp' --exclude='/mnt' \
--exclude='/media' --exclude='/lost+found' \
/
# ============================================
# PART 3: VERIFY ARCHIVE INTEGRITY
# ============================================
tar -tzf /backup/full-$(date +%Y%m%d).tar.gz > /dev/null && echo "Archive OK"
# ============================================
# PART 4: RSYNC MIRROR OF USER DATA
# ============================================
sudo mkdir -p /backup/rsync/home
rsync -avh --delete /home/ /backup/rsync/home/
# ============================================
# PART 5: DRY RUN BEFORE DELETE
# ============================================
rsync -avhn --delete /home/ /backup/rsync/home/
# ============================================
# PART 6: REMOTE BACKUP OVER SSH
# ============================================
rsync -avz -e ssh /home/ backup-user@192.168.1.50:/backups/home/
# ============================================
# PART 7: CREATE BACKUP SCRIPT
# ============================================
cat > /usr/local/bin/backup.sh << 'EOF'
#!/bin/bash
set -euo pipefail
BACKUP_DIR="/backup"
DATE=$(date +%Y%m%d)
LOG="/var/log/backup.log"
echo "$(date): Starting backup" >> "$LOG"
# Full system archive
tar -czpf "$BACKUP_DIR/full-$DATE.tar.gz" \
--exclude='/proc' --exclude='/sys' --exclude='/dev' \
--exclude='/run' --exclude='/tmp' --exclude='/mnt' \
--exclude='/media' --exclude='/lost+found' \
/ >> "$LOG" 2>&1
# Verify archive
if tar -tzf "$BACKUP_DIR/full-$DATE.tar.gz" > /dev/null 2>&1; then
echo "$(date): Backup verified: full-$DATE.tar.gz" >> "$LOG"
else
echo "$(date): BACKUP FAILED" >> "$LOG" >&2
exit 1
fi
EOF
sudo chmod +x /usr/local/bin/backup.sh
# ============================================
# PART 8: SYSTEMD TIMER
# ============================================
sudo tee /etc/systemd/system/backup.service << 'EOF'
[Unit]
Description=Daily backup
[Service]
Type=oneshot
ExecStart=/usr/local/bin/backup.sh
EOF
sudo tee /etc/systemd/system/backup.timer << 'EOF'
[Unit]
Description=Run daily backup
[Timer]
OnCalendar=*-*-* 02:00:00
Persistent=true
[Install]
WantedBy=timers.target
EOF
sudo systemctl daemon-reload
sudo systemctl enable --now backup.timer
# ============================================
# PART 9: RESTORE DRILL
# ============================================
mkdir -p /tmp/restore-test
tar -xzf /backup/full-$(date +%Y%m%d).tar.gz -C /tmp/restore-test
ls -la /tmp/restore-test/etc/
# ============================================
# PART 10: VERIFICATION CHECKLIST
# ============================================
# Archive created? ls -lh /backup/
# Archive readable? tar -tzf /backup/full-*.tar.gz > /dev/null
# Restore works? tar -xzf /backup/full-*.tar.gz -C /tmp/test
# Timer active? systemctl list-timers backup.timer
# Logs show success? tail /var/log/backup.log
The ten parts covered the complete backup workflow: directory creation, full archive creation, integrity verification, rsync mirroring, dry-run safety, remote backup, script automation, systemd timer scheduling, restore drill, and a final verification checklist.
Quick Reference
Backup Tool Selection
| Tool | Best For | Preserves | Output |
|---|---|---|---|
tar | Archival, full system | Permissions, ownership | Single archive file |
rsync | File synchronization | Permissions, timestamps | Mirrored file tree |
dd | Disk imaging | Everything (bit-for-bit) | Raw image file |
tar Command Flags
| Flag | Purpose |
|---|---|
-c | Create archive |
-x | Extract archive |
-t | List contents |
-z | gzip compression |
-j | bzip2 compression |
-J | xz compression |
-v | Verbose |
-p | Preserve permissions |
-f | Specify filename |
rsync Command Flags
| Flag | Purpose |
|---|---|
-a | Archive mode |
-v | Verbose |
-h | Human-readable |
-z | Compress transfer |
-n | Dry run |
--delete | Remove extraneous files |
Backup Exclusions
| Directory | Reason |
|---|---|
/proc | Virtual filesystem |
/sys | Virtual filesystem |
/dev | Device files |
/tmp | Temporary data |
/run | Runtime data |
/mnt | Mount point |
/media | Removable media |
Scheduling Methods
| Method | Missed Run Handling | Logging |
|---|---|---|
cron | Does not run | Manual redirect |
systemd timer | Runs with Persistent=true | Journal integration |
Best Practices
โ Do This:
# Exclude virtual filesystems from system backups
tar --exclude='/proc' --exclude='/sys' -czf backup.tar.gz / # โ
# Use -p to preserve permissions
tar -czpf backup.tar.gz /etc # โ
# Dry-run rsync before --delete
rsync -avhn --delete /src/ /dest/ # โ
# Verify archive after creation
tar -tzf backup.tar.gz > /dev/null && echo "OK" # โ
# Test restore periodically
tar -xzf backup.tar.gz -C /tmp/restore-test # โ
# Use systemd timer for missed runs
# Persistent=true in [Timer] section # โ
โ Don’t Do This:
# Back up virtual filesystems
tar -czf backup.tar.gz /proc /sys /dev # โ
# Use --delete without dry run
rsync -av --delete /src/ /dest/ # โ
# Forget the trailing slash on rsync source
rsync -av /home/user /backup/ # creates /backup/user/user/ # โ
# Store backup on same disk as source
tar -czf /home/user/backup.tar.gz /home/user # โ
# Skip restore verification
# (untested backups are hopes) # โ
Common Pitfalls
| Pitfall | Why It Happens | Fix |
|---|---|---|
| Archive missing permissions | -p flag omitted | Use tar -czpf |
Backup includes /proc errors | Virtual filesystem included | Add --exclude='/proc' |
| rsync creates nested directory | Trailing slash forgotten | Use /source/ not /source |
--delete removes wanted files | Dry run skipped | Always -n first |
| Timer doesnโt run after outage | cron has no catch-up | Use systemd Persistent=true |
| Backup unreadable at restore | Never verified | Test restore drill |
| Backup on same disk fails together | No geographic separation | Store offsite or remote |
Real-World Examples
1. Backup /etc Configuration
sudo tar -czpf /backup/etc-$(date +%F).tar.gz /etc
2. Backup User Home Directory
tar -czpf /backup/home-$(date +%F).tar.gz /home/user
3. Full System Archive
sudo tar -czpf /backup/full.tar.gz --exclude='/proc' --exclude='/sys' /
4. Local rsync Mirror
rsync -avh --delete /home/user/ /backup/home/user/
5. Remote rsync Backup
rsync -avz /data/ user@backup-server:/backups/data/
6. Dry Run rsync
rsync -avhn --delete /data/ /backup/data/
7. Verify tar Archive
tar -tzf /backup/full.tar.gz > /dev/null && echo "Valid"
8. Extract Single File from Archive
tar -xzf /backup/etc.tar.gz etc/nginx/nginx.conf
9. Create Backup Cron Job
0 2 * * * /usr/local/bin/backup.sh >> /var/log/backup.log 2>&1
10. Systemd Timer for Backup
[Timer]
OnCalendar=*-*-* 02:00:00
Persistent=true
Visual
Backup Strategy Layers
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ BACKUP STRATEGY LAYERS โ
โ โ
โ Layer 1: TAR ARCHIVES โ
โ Full system snapshots, compressed, portable โ
โ โโโ Best for: archival, disaster recovery โ
โ โ
โ Layer 2: RSYNC MIRRORS โ
โ File-level synchronization, individual file restore โ
โ โโโ Best for: daily backup, quick recovery of single files โ
โ โ
โ Layer 3: REMOTE STORAGE โ
โ Offsite copy, geographic separation โ
โ โโโ Best for: protection against site-wide failure โ
โ โ
โ Layer 4: AUTOMATION โ
โ Cron or systemd timer ensures consistency โ
โ โโโ Best for: eliminating human error and forgetfulness โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
tar vs rsync Decision
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ CHOOSING BETWEEN tar AND rsync โ
โ โ
โ Need a single portable archive? โ
โ โ โ
โ โโโ YES โโโถ tar -czpf backup.tar.gz /path โ
โ โ โ
โ โโโ NO โ
โ โ โ
โ โผ โ
โ Need to restore individual files easily? โ
โ โ โ
โ โโโ YES โโโถ rsync -av /source/ /backup/ โ
โ โ โ
โ โโโ NO โ
โ โ โ
โ โผ โ
โ Need incremental transfer? โ
โ โ โ
โ โโโ YES โโโถ rsync (only transfers changes) โ
โ โ โ
โ โโโ NO โโโถ tar (full archive each time) โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
The Restore Drill
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ RESTORE DRILL VERIFICATION โ
โ โ
โ 1. Create archive โ
โ tar -czpf /backup/test.tar.gz /etc โ
โ โ
โ 2. List contents (integrity check) โ
โ tar -tzf /backup/test.tar.gz > /dev/null โ
โ โ Exit 0 = archive readable โ
โ โ
โ 3. Extract to clean directory โ
โ mkdir /tmp/restore-test โ
โ tar -xzf /backup/test.tar.gz -C /tmp/restore-test โ
โ โ
โ 4. Verify files present โ
โ ls -la /tmp/restore-test/etc/ โ
โ โ Files should be readable and complete โ
โ โ
โ 5. Clean up โ
โ rm -rf /tmp/restore-test โ
โ โ
โ Untested backups are not backups. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Cron vs systemd Timer
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ SCHEDULING: CRON vs SYSTEMD TIMER โ
โ โ
โ CRON โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ 0 2 * * * /backup.sh โ โ
โ โ โ โ
โ โ Simple syntax. โ โ
โ โ No catch-up for missed runs. โ โ
โ โ Logs need manual redirection. โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ
โ SYSTEMD TIMER โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ [Timer] โ โ
โ โ OnCalendar=*-*-* 02:00:00 โ โ
โ โ Persistent=true โ โ
โ โ โ โ
โ โ Catches up on missed runs. โ โ
โ โ Journal integration for logs. โ โ
โ โ Same management as other services. โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ
โ Modern Linux: prefer systemd timers. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Summary
| Item | Value |
|---|---|
| Archive tool | tar for compressed backups |
| Sync tool | rsync for file-level mirroring |
| Image tool | dd for bit-for-bit disk copies |
| Archive creation | tar -czpf backup.tar.gz /path |
| Archive verify | tar -tzf backup.tar.gz > /dev/null |
| rsync mirror | rsync -avh --delete /src/ /dest/ |
| rsync dry run | rsync -avhn --delete /src/ /dest/ |
| Remote backup | rsync -avz user@host:/path/ |
| Automation (cron) | 0 2 * * * /path/backup.sh |
| Automation (systemd) | OnCalendar=*-*-* 02:00:00 |
| Exclusions | /proc, /sys, /dev, /tmp, /run |
| Verification | Restore drill |
Key takeaways:
- A backup is not a backup until it has been restored. Archive integrity checks are necessary but not sufficient. Periodically extract a backup to a temporary location and confirm the files are present and readable.
- Geographic separation is fundamental. A backup stored on the same disk as the original data provides no protection against disk failure. Store backups on a different disk, a different server, or offsite.
tarcreates archives;rsyncmaintains mirrors. Usetarwhen you need a single portable file. Usersyncwhen you need to restore individual files quickly or transfer only changes.- Exclude virtual filesystems from system backups. The
/proc,/sys,/dev,/run, and/tmpdirectories contain no persistent data. Including them wastes space and may cause errors. rsync --deleterequires a dry run. The--deleteflag removes files from the destination that are not in the source. If the source is incomplete or unmounted,--deletewill propagate the error. Always preview with-nfirst.-ppreserves permissions intar. Without the-pflag,tarmay not preserve ownership and permission information, which is critical for system backups.systemdtimers handle missed runs. Unlikecron,systemdtimers withPersistent=truerun missed jobs when the system becomes available. This is the preferred method on modern Linux.
Remember: Setting up a backup is a technical task. Designing a backup strategy is a judgment task. The commands in this chapter will create archives and synchronize files. The judgmentโdeciding what to back up, how often, where to store it, and how to verify itโis what separates a backup that exists from a backup that works. The LFCA exam tests both. It expects you to know the flags for tar and rsync, but it also expects you to understand why a restore drill is mandatory, why virtual filesystems should be excluded, and why a backup on the same disk is not a backup. Master the commands, but practice the judgment.
Stop using slow, ad-bloated tool sites! ๐คฎ
๐ Search “KandZ Tools” on Google to use many professional utilities for free.
KandZ.me is the ultimate minimalist hub for:
โ
Finance (Mortgage, Interest, Inflation)
โ
Tech (Base64, JSON, Dev Suite, IP)
โ
Health (BMI, BMR, TDEE)
โ
Productivity (Timer, Workspace, QR)
โก๏ธ Fast & Private
๐ No data leaves your device
๐ 100% Free
๐ Use it now: https://tools.kandz.me
๐ Bookmark itโyouโll need it later!