LFCA 67 ๐ง Backup Concepts โ Full, Incremental, Differential
A backup strategy is not a single tool or a single command. It is a plan that answers three questions: what to back up, how often, and how to restore it. The three fundamental backup types โ full, incremental, and differential โ are the building blocks of that plan. Each one trades storage space, backup time, and restore complexity in a different way.
The LFCA exam places backup and recovery under System Administration Fundamentals, which carries 20% of the total weight . The competency list explicitly includes “Implement backup strategies” and “Disaster Recovery” with recovery planning . Knowing the definitions is not enough. The exam tests whether you understand the trade-offs โ why you would choose one type over another, and what happens when you need to restore.
Key point: A full backup copies everything, every time. A differential backup copies everything that changed since the last full backup. An incremental backup copies everything that changed since the last backup of any type . The difference between differential and incremental is what each one references: the full backup, or the most recent backup. That single distinction determines how many files you need to restore.
Why backup types exist
A backup strategy is a compromise between three competing concerns: how much space the backups consume, how long the backup takes to run, and how long the restore takes when you need it. No single type optimizes all three.
The storage problem. A full backup copies every file every time. For a system with 500 GB of data, that is 500 GB per backup. Run it daily for a week, and you have 3.5 TB of backups. Incremental backups copy only the files that changed since the last backup, which might be a few megabytes on a quiet day . The difference in storage requirements is the primary reason incremental backups exist.
The backup window problem. A full backup of a large system takes hours. If it runs during the day, it competes with users for disk I/O and network bandwidth. Incremental backups take minutes because they copy so little. This allows more frequent backups โ hourly instead of nightly โ without disrupting the system.
The restore problem. This is the hidden cost of incremental backups. A full backup restores in one step: copy everything. A differential backup restores in two steps: copy the full backup, then copy the most recent differential. An incremental backup restores in N steps: copy the full backup, then every incremental backup in order, from oldest to newest . If you have a weekly full backup and daily incrementals, restoring from Friday requires the full backup plus five incremental files. If any one of those files is corrupted, the restore fails.
The trade-off. Full backups are simple to restore but expensive to store. Incremental backups are cheap to store but complex to restore. Differential backups sit in the middle: they are larger than incremental backups (because each differential grows as more changes accumulate since the last full backup), but restoring requires only two files instead of many . Most production systems combine all three: a periodic full backup, supplemented by differential and incremental backups .
a. Full Backups
A full backup copies the entire dataset โ every file, every directory, every configuration โ regardless of whether it has changed since the last backup . It is the foundation of every backup strategy. Without a full backup, neither differential nor incremental backups have a reference point.
# A full backup with tar
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc /var/www
# A full backup with rsync
rsync -aAXv --delete / /backup/full-system/ \
--exclude={/dev/*,/proc/*,/sys/*,/tmp/*,/run/*,/mnt/*}
The tar command creates a compressed archive of the specified directories. The -c flag creates the archive, -z compresses it with gzip, -p preserves permissions, and -f specifies the output file . The $(date +%F) substitution appends the current date to the filename, so each full backup is separate. The rsync command synchronizes the entire filesystem to a backup directory, excluding pseudo-filesystems that should not be backed up .
The advantage of a full backup is simplicity. The restore is a single command: extract the archive or synchronize the backup directory back to the source. There is no dependency chain, no “restore the full, then restore these six incrementals in order.” One file, one restore .
The disadvantage is cost. Every full backup contains the same data. If the dataset is 100 GB and you run full backups weekly, you consume 100 GB of storage every week for data that has barely changed. For systems with large datasets and slow change rates, this is wasteful.
b. Differential Backups
A differential backup copies everything that has changed since the last full backup . The key word is “full.” A differential backup does not care about other differential backups. It only compares the current state to the state at the time of the last full backup.
# A differential backup with tar (using GNU tar's --newer flag)
tar -czpf /backup/diff-$(date +%F).tar.gz \
--newer="$(cat /backup/last-full-date)" \
/home /etc /var/www
The --newer flag tells tar to include only files modified after the timestamp stored in /backup/last-full-date. The timestamp file is updated when a full backup runs. This produces a differential backup: everything changed since that date.
The behavior of a differential backup over time is important. On Monday, after a Sunday full backup, the differential contains Monday’s changes. On Tuesday, the differential contains Monday’s and Tuesday’s changes. On Wednesday, it contains Monday’s, Tuesday’s, and Wednesday’s. The differential grows larger each day because it accumulates every change since the full backup .
This growth is the distinguishing characteristic of differential backups. They start small and get progressively larger. An incremental backup, by contrast, stays roughly the same size every day because it only references the previous backup, not the full one.
The restore process for a differential backup requires two files: the last full backup and the most recent differential . You do not need the differentials from Monday, Tuesday, and Wednesday โ only the most recent one, because it contains all the changes since the full backup. This is the advantage of differential over incremental: fewer files to restore, less chance of a corrupted link in the chain.
c. Incremental Backups
An incremental backup copies everything that has changed since the last backup of any type โ whether that was a full backup, a differential backup, or another incremental backup . This is the critical distinction. Differential backups reference the full backup. Incremental backups reference whatever backup ran most recently.
# An incremental backup with rsync
rsync -aAXv --link-dest=/backup/previous/ /home /backup/current/
# The --link-dest flag creates hard links to unchanged files,
# so only changed files consume new space.
The rsync command with --link-dest is the classic incremental backup technique. Unchanged files are hard-linked to the previous backup, so they do not consume additional space. Only files that have changed are copied as new data . The result is a directory that looks like a full backup but shares most of its data with the previous backup.
The size behavior of incremental backups is flat. Monday’s incremental contains Monday’s changes. Tuesday’s contains Tuesday’s changes. Wednesday’s contains Wednesday’s changes. Each one is roughly the same size, assuming the daily change rate is constant. Unlike differential backups, which grow, incremental backups stay small .
The restore process is the cost. To restore from incremental backups, you must restore the last full backup, then every incremental backup in sequence, from oldest to newest . If you have a weekly full backup and daily incrementals, restoring from Friday requires the full backup plus five incremental files. Each one must be applied in order. If the third incremental is corrupted, the restore stops there, and you lose everything after that point.
The xfsrestore command illustrates this cumulative restore process for XFS filesystems. The -r option “cumulatively restore[s] all data starting from a level 0 backup and working through all available incremental backups” . The command must be run multiple times, once for the full backup and once for each incremental, in order.
Complete Example Session
This session demonstrates the three backup types using tar and rsync, then walks through the restore process for each.
# ============================================
# PART 1: THE FULL BACKUP
# ============================================
# Create a full backup of /home and /etc
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc
# Record the timestamp for differential backups
date +%F > /backup/last-full-date
# Verify the backup
tar tzf /backup/full-2025-05-07.tar.gz | head -20
# ============================================
# PART 2: THE DIFFERENTIAL BACKUP
# ============================================
# Two days later, a file is modified
echo "new config" >> /etc/myapp.conf
# Create a differential backup (changes since the full backup)
tar -czpf /backup/diff-$(date +%F).tar.gz \
--newer="$(cat /backup/last-full-date)" \
/home /etc
# The differential contains myapp.conf but not unchanged files.
# ============================================
# PART 3: THE INCREMENTAL BACKUP WITH RSYNC
# ============================================
# First full backup
rsync -aAXv /home/ /backup/rsync/full/
# Next day: incremental backup with hard links
rsync -aAXv --link-dest=/backup/rsync/full/ \
/home/ /backup/rsync/inc-2025-05-08/
# Next day: another incremental, linking to the previous one
rsync -aAXv --link-dest=/backup/rsync/inc-2025-05-08/ \
/home/ /backup/rsync/inc-2025-05-09/
# Unchanged files are hard links. Only new files consume space.
# ============================================
# PART 4: RESTORING FROM A FULL BACKUP
# ============================================
# One command, everything restored
mkdir -p /tmp/restore-full
tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-full
# ============================================
# PART 5: RESTORING FROM A DIFFERENTIAL BACKUP
# ============================================
# Step 1: restore the full backup
mkdir -p /tmp/restore-diff
tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-diff
# Step 2: restore the most recent differential
tar -xzpf /backup/diff-2025-05-09.tar.gz -C /tmp/restore-diff
# Two files. The differential contains all changes since the full.
# ============================================
# PART 6: RESTORING FROM INCREMENTAL BACKUPS
# ============================================
# Step 1: restore the full backup
mkdir -p /tmp/restore-inc
rsync -aAXv /backup/rsync/full/ /tmp/restore-inc/
# Step 2: restore each incremental in order
rsync -aAXv /backup/rsync/inc-2025-05-08/ /tmp/restore-inc/
rsync -aAXv /backup/rsync/inc-2025-05-09/ /tmp/restore-inc/
# Every file in the chain must be present and uncorrupted.
# ============================================
# PART 7: THE SIZE COMPARISON
# ============================================
# Full backups: same size every time
du -sh /backup/full-*.tar.gz
# 100M full-2025-05-07.tar.gz
# Differential backups: grow over time
du -sh /backup/diff-*.tar.gz
# 5M diff-2025-05-08.tar.gz (Monday changes)
# 12M diff-2025-05-09.tar.gz (Monday + Tuesday changes)
# Incremental backups: roughly constant
du -sh /backup/rsync/inc-*/ | tail -3
# 5M inc-2025-05-08/
# 5M inc-2025-05-09/
# ============================================
# PART 8: THE RESTORE TIME COMPARISON
# ============================================
# Full: 1 file, fastest
time tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-full
# Differential: 2 files, moderate
time (tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore-diff && \
tar -xzpf /backup/diff-2025-05-09.tar.gz -C /tmp/restore-diff)
# Incremental: N files, slowest
time (rsync -aAXv /backup/rsync/full/ /tmp/restore-inc/ && \
rsync -aAXv /backup/rsync/inc-2025-05-08/ /tmp/restore-inc/ && \
rsync -aAXv /backup/rsync/inc-2025-05-09/ /tmp/restore-inc/)
# ============================================
# PART 9: THE COMBINED STRATEGY
# ============================================
# Weekly full backup on Sunday
0 2 * * 0 tar -czpf /backup/full-$(date +\%F).tar.gz /home /etc
# Daily differential backup Monday through Saturday
0 2 * * 1-6 tar -czpf /backup/diff-$(date +\%F).tar.gz \
--newer="$(cat /backup/last-full-date)" /home /etc
# This gives the simplicity of differential restore
# with the storage savings of not running full backups daily.
# ============================================
# PART 10: THE BACKUP VERIFICATION
# ============================================
# Verify a tar archive is readable
tar tzf /backup/full-2025-05-07.tar.gz > /dev/null && echo "OK"
# Verify rsync backup is complete
rsync -aAXvn /home/ /backup/rsync/full/ --delete
# The -n flag (dry run) shows what would change.
# No output means the backup is current.
The ten parts cover the full backup, the differential backup, the incremental backup with rsync, restoring from a full backup, restoring from a differential backup, restoring from incremental backups, the size comparison, the restore time comparison, the combined strategy, and backup verification.
Quick Reference
The Three Backup Types
| Type | Copies | References | Restore Files |
|---|---|---|---|
| Full | Everything | Nothing | 1 |
| Differential | Changes since last full | Last full backup | 2 |
| Incremental | Changes since last backup | Most recent backup | 1 + N |
The Trade-Off Matrix
| Concern | Full | Differential | Incremental |
|---|---|---|---|
| Storage per backup | Largest | Moderate, grows | Smallest |
| Backup speed | Slowest | Moderate | Fastest |
| Restore speed | Fastest | Moderate | Slowest |
| Restore complexity | Lowest | Moderate | Highest |
| Files to restore | 1 | 2 | 1 + N |
The Common Commands
| Tool | Full Backup | Incremental |
|---|---|---|
| tar | tar -czpf archive.tar.gz /path | tar --newer=date |
| rsync | rsync -aAXv /src/ /dest/ | rsync --link-dest=prev |
| dd | dd if=/dev/sda of=disk.img | Not suited |
The Strategy Guidelines
| Scenario | Recommended Strategy |
|---|---|
| Small dataset, fast restore | Full daily |
| Large dataset, moderate restore | Weekly full + daily differential |
| Very large dataset, space-constrained | Weekly full + daily incremental |
| Mission-critical | Full + differential + off-site copies |
Best Practices
โ Do This:
# Run a full backup before a differential chain starts
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc # โ
# Record the full backup timestamp for differential backups
date +%F > /backup/last-full-date # โ
# Use --link-dest for space-efficient incremental backups
rsync -aAXv --link-dest=/backup/previous/ /home /backup/current/ # โ
# Test the restore, not just the backup
tar -xzpf /backup/full.tar.gz -C /tmp/restore-test # โ
# Follow the 3-2-1 rule: 3 copies, 2 media, 1 off-site
# The live system is copy 1. Backups are copies 2 and 3. # โ
โ Don’t Do This:
# Don't run only incremental backups forever
# You need a full backup as the foundation. # โ
# Don't assume a differential backup is small
# It grows every day until the next full backup. # โ
# Don't skip the full backup in an incremental chain
# The restore will fail without it. # โ
# Don't store backups on the same disk as the data
# A disk failure destroys both. # โ
Common Pitfalls
| Pitfall | Why It Happens | Fix |
|---|---|---|
| Restore fails | Missing an incremental in the chain | Verify all files are present |
| Differential grows too large | Full backup not run often enough | Increase full backup frequency |
| Backup takes too long | Running full backup daily | Switch to differential or incremental |
| Space exhausted | Too many full backups retained | Rotate and delete old backups |
| Corrupted backup unknown | Never tested the restore | Restore to a test location periodically |
Real-World Examples
1. Full Backup with tar
tar -czpf /backup/full-$(date +%F).tar.gz /home /etc
2. Full Backup with rsync
rsync -aAXv / /backup/full-system/ --exclude={/proc,/sys,/dev}
3. Differential Backup
tar -czpf /backup/diff-$(date +%F).tar.gz --newer="$(cat /backup/last-full-date)" /home
4. Incremental with rsync
rsync -aAXv --link-dest=/backup/previous/ /home /backup/current/
5. Restore Full
tar -xzpf /backup/full-2025-05-07.tar.gz -C /tmp/restore
6. Restore Differential
tar -xzpf /backup/full.tar.gz -C /tmp/restore && tar -xzpf /backup/diff.tar.gz -C /tmp/restore
7. Restore Incremental
rsync -aAXv /backup/full/ /tmp/restore/ && rsync -aAXv /backup/inc-1/ /tmp/restore/
8. Verify tar Archive
tar tzf /backup/full.tar.gz > /dev/null && echo "OK"
9. Combined Strategy (cron)
0 2 * * 0 tar -czpf /backup/full-$(date +\%F).tar.gz /home
0 2 * * 1-6 tar -czpf /backup/diff-$(date +\%F).tar.gz --newer="$(cat /backup/last-full-date)" /home
10. 3-2-1 Rule
# 3 copies: live + local backup + off-site backup
# 2 media: disk + tape (or disk + cloud)
# 1 off-site: rsync to remote server
rsync -avz /backup/ user@remote:/backup/
Visual
The Three Backup Types
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ FULL BACKUP โ
โ โ
โ Sunday: [=========================] 100M โ
โ Monday: [=========================] 100M โ
โ Tuesday: [=========================] 100M โ
โ โ
โ Every backup is complete. โ
โ Restore: 1 file. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ DIFFERENTIAL BACKUP โ
โ โ
โ Sunday: [=========================] 100M โ (full)
โ Monday: [==] 5M โ (since full)
โ Tuesday: [=====] 12M โ (since full)
โ โ
โ Each differential references the full. โ
โ Restore: full + most recent differential. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ INCREMENTAL BACKUP โ
โ โ
โ Sunday: [=========================] 100M โ (full)
โ Monday: [==] 5M โ (since Sunday)
โ Tuesday: [==] 5M โ (since Monday)
โ โ
โ Each incremental references the previous. โ
โ Restore: full + every incremental in order. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
The Restore Chain
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ RESTORE FROM FULL โ
โ โ
โ Full โโ> Restored. Done. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ RESTORE FROM DIFFERENTIAL โ
โ โ
โ Full โโ> Differential โโ> Restored. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ RESTORE FROM INCREMENTAL โ
โ โ
โ Full โโ> Inc1 โโ> Inc2 โโ> Inc3 โโ> ... โ
โ โ
โ Every file must be present. โ
โ Every file must be uncorrupted. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
The Size Over Time
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ SIZE OVER TIME โ
โ โ
โ Full: constant (large) โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ
โ Differential: grows (moderate) โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โโ โ
โ โโโโโโโโ โ
โ โโโโโโโโโโโโโโ โ
โ โ
โ Incremental: constant (small) โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โโ โ
โ โโ โ
โ โโ โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
The 3-2-1 Rule
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ THE 3-2-1 RULE โ
โ โ
โ 3 copies: โ
โ 1. Live system โ
โ 2. Local backup โ
โ 3. Off-site backup โ
โ โ
โ 2 different media: โ
โ e.g., disk + tape, or disk + cloud โ
โ โ
โ 1 off-site: โ
โ Protects against fire, theft, ransomware โ
โ โ
โ The live system is not a backup. โ
โ It is the source. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Summary
| Item | Value |
|---|---|
| Full backup | Everything, every time |
| Differential backup | Changes since last full backup |
| Incremental backup | Changes since last backup of any type |
| Full restore | 1 file |
| Differential restore | 2 files (full + most recent diff) |
| Incremental restore | 1 + N files (full + all incrementals) |
| Differential size | Grows over time |
| Incremental size | Constant |
| Common tool | tar for archives, rsync for synchronization |
| rsync incremental | --link-dest for hard-linked unchanged files |
| Best practice | 3-2-1: 3 copies, 2 media, 1 off-site |
Key takeaways:
- Full backups copy everything; differential and incremental backups copy only what changed. The distinction between differential and incremental is what they reference: differential references the last full backup, incremental references the last backup of any type .
- Differential backups grow over time; incremental backups stay roughly constant. A differential on Monday contains one day of changes. On Tuesday, it contains two days. On Wednesday, three. An incremental always contains one day (or one backup period) of changes .
- Restore complexity is the hidden cost of incremental backups. A full backup restores in one step. A differential restores in two. An incremental restores in N steps, where N is the number of incremental backups since the last full backup. Every file in the chain must be present and uncorrupted .
- Most production systems use a combination. A weekly full backup provides the foundation. Daily differential or incremental backups capture changes. The choice between differential and incremental depends on whether you prioritize restore simplicity or storage efficiency .
tarandrsyncare the standard Linux backup tools.tarcreates compressed archives suitable for full and differential backups.rsyncwith--link-destcreates space-efficient incremental backups using hard links to unchanged files .- The 3-2-1 rule is the industry standard for backup strategy. Keep three copies of your data, on two different types of media, with at least one copy off-site. The live system is not a backup โ it is the source. Backups are the additional copies .
- Always test the restore, not just the backup. A backup that cannot be restored is not a backup. Restore to a test location periodically to verify that the process works and the data is intact .
Remember: Full, differential, and incremental backups are not competing strategies. They are building blocks. A full backup is the foundation. Differential backups sit on top of it, capturing everything since the last full. Incremental backups capture everything since the last backup of any kind. The choice between them is a trade-off between storage space, backup time, and restore complexity. Full backups are simple to restore but expensive to store. Incremental backups are cheap to store but complex to restore. Differential backups sit in the middle. The 3-2-1 rule ensures that no single failure destroys all copies. And the only backup that matters is the one you have tested restoring.
Stop using slow, ad-bloated tool sites! ๐คฎ
๐ Search “KandZ Tools” on Google to use many professional utilities for free.
KandZ.me is the ultimate minimalist hub for:
โ
Finance (Mortgage, Interest, Inflation)
โ
Tech (Base64, JSON, Dev Suite, IP)
โ
Health (BMI, BMR, TDEE)
โ
Productivity (Timer, Workspace, QR)
โก๏ธ Fast & Private
๐ No data leaves your device
๐ 100% Free
๐ Use it now: https://tools.kandz.me
๐ Bookmark itโyouโll need it later!