Create an hourly EFS backup plan with a dedicated IAM role for a 100-minute RPO

Answer Correct answer: A — Use a new IAM role and backup plan on an hourly schedule, and allow that role to use the KMS key.

A company stores and manages documents in an Amazon Elastic File System (Amazon EFS) file system. The file system is encrypted with an AWS Key Management Service (AWS KMS) key. The file system is mounted to an Amazon EC2 instance that runs proprietary software. The company has enabled automatic backups for the file system. The automatic backups use the AWS Backup default backup plan. A solutions architect must ensure that deleted documents can be recovered within an RPO of 100 minutes. Which solution will meet these requirements?

  1. Create a new IAM role. Create a new backup plan. Use the new IAM role to create backups. Update the KMS key policy to allow the new IAM role to use the key. Implement an hourly backup schedule for the file system. Correct Answer
  2. Create a new backup plan. Update the KMS key policy to allow the AWSServiceRoleForBackup IAM role to use the key. Implement a custom cron expression to run a backup of the file system every 30 minutes.
  3. Create a new IAM role. Use the existing backup plan. Update the KMS key policy to allow the new IAM role to use the key. Enable continuous backups for point-in-time recovery.
  4. Use the existing backup plan. Update the KMS key policy to allow the AWSServiceRoleForBackup IAM role to use the key. Enable Cross-Region Replication for the file system.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Meeting a 100-minute RPO requires both a custom backup plan on an hourly schedule and a new IAM role whose key policy is allowed to use the KMS key, so deleted data can be restored from a point in time.

Documents in an encrypted EFS file system must be recoverable within 100 minutes, but the current setup uses the AWS Backup default plan. The default plan runs daily, so the schedule and the KMS key policy both need to change.

Assuming the AWS Backup default plan can be tightened, or that continuous backups exist for EFS. Backup plans cannot run more often than hourly, and EFS does not support continuous point-in-time recovery, so the 30-minute cron in B is also invalid.

Community Discussion (9 comments)

VerRi 👍 7 Selected: A
The default backup plan is once a day, which cannot meet the RPO, so C and D are out. We need both EventBridge and Lambda functions to frequently backup the EFS, so B is out.
Syre 👍 1 Selected: A
https://community.aws/content/2iCkeS4XUmYdFf8Mlz6C7DFg5K3/protecting-amazon-s3-using-aws-backup
053081f 👍 4 Selected: A
I checked the AWS Backup console and you cannot setup backup plan less than 1 hour, so 30 min backup(B) will be excluded.
titi_r 👍 1 Selected: A
Answer A.
Aesthet 👍 4 Selected: A
C is not supported, see here: https://docs.aws.amazon.com/aws-backup/latest/devguide/backup-feature-availability.html#features-by-resource B is not possible (minimum is 1 hour, according to https://aws.amazon.com/blogs/storage/automating-backups-and-optimizing-backup-costs-for-amazon-efs-using-aws-backup/#:~:text=cron%20expression%20that%20creates%20backups%20as%20frequently%20as%20hourly). So I vote for A
pangchn 👍 2 Selected: B
B Using the AWS Backup console, you can choose a frequency of every 12 hours, daily, weekly, or monthly. You can also create a cron expression that creates backups as frequently as hourly ref: https://aws.amazon.com/blogs/storage/automating-backups-and-optimizing-backup-costs-for-amazon-efs-using-aws-backup/ PITR is not supported for EFS mentioned by djangoUnchained, so C is out From AWS console, the most frequently backup is daily.
AWSPro1234 👍 1
Answer C.
Dgix 👍 3 Selected: A
First of all, using the existing default backup plan means backups only once a day, which disqualifies both C and D. We are thus left with A and B, which both fulfil the RPO. B is slightly more wasteful in that 30-minute backups are overkill. Also, B requires a custom cron task to be set up using EventBridge as it is a non-standard one for AWS Backup. A, however, can be accomplished without extra operational overhead. Therefore, A.
CMMC 👍 1 Selected: C
Creating a new IAM role and updating the KMS key policy to allow the role to use the key ensures that the backup mechanism has the necessary permissions for encryption. Enabling continuous backups for point-in-time recovery to increases the likelihood of being able to recover deleted documents within the specified RPO of 100 minutes.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A new backup plan with an hourly schedule is the finest granularity AWS Backup supports, which fits inside the 100-minute RPO. Because the file system is encrypted with a customer managed KMS key, the plan must run under a new IAM role, and that role must be granted use of the key by updating the key policy, otherwise the backup silently cannot encrypt the data.

Why the Other Options Are Wrong

B: AWS Backup backup plans cannot be scheduled more frequently than once per hour, so a 30-minute cron expression is rejected. C: Amazon EFS does not support continuous backups for point-in-time recovery, as shown in the AWS Backup feature availability table. D: Cross-Region Replication for EFS protects against a regional disaster but does not shorten the recovery point inside the primary Region, so it cannot deliver a 100-minute RPO for deleted documents.

Community Comment Notes

The community was unanimous at 87 votes. Commenters verified in the AWS Backup console that the minimum backup plan interval is one hour and cited the feature availability table showing that continuous backups are not supported for EFS.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide