Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews
Backup is the process of creating one or more extra copies of important data — files, folders, databases, or entire systems — and storing them in a separate, safe location so that the original data can be restored if it is ever lost, corrupted, deleted, or damaged. Data Recovery is the complementary process of retrieving that lost, corrupted, or inaccessible data, either from a previously made backup or, when no backup exists, by using specialized recovery techniques and tools to salvage data directly from a damaged storage device. Together, Backup and Data Recovery form the safety net that protects individuals and organizations from losing valuable digital information.

Day-to-Day Example: When your phone automatically saves your WhatsApp chats and photos to Google Drive or iCloud every night, that is a backup. If your phone is later lost or reset and you sign in again, the app pulling those chats and photos back down onto the new phone is data recovery in action.
Backup and Data Recovery are essential because data can be lost at any moment due to countless unpredictable causes — hardware failure, accidental deletion, theft, fire, flood, ransomware, software bugs, or simple human error. Businesses today run almost entirely on digital data (customer records, financial ledgers, source code, medical histories), and losing this data even temporarily can mean lost revenue, legal penalties, reputational damage, or in extreme cases, the complete collapse of an organization. A solid backup and recovery strategy ensures continuity, compliance, and peace of mind.
Day-to-Day Example: A small business that keeps its only customer database on a single office laptop, with no backup, can lose years of billing history and client contacts in seconds if that laptop is stolen or its disk fails — a proper backup strategy would have prevented total loss.
A backup system works by systematically copying data from a source location (a laptop, server, or database) to a destination location (an external drive, network storage, or the cloud) according to a defined schedule and method. The backup software tracks what has changed since the last copy, transfers that data securely, and verifies that the copy is complete and uncorrupted. Data recovery, in turn, works by either restoring a chosen backup version back onto the original or a new system, or — when no backup exists — using specialized software to scan a damaged/corrupted storage medium sector by sector to reconstruct lost files from whatever traces remain on the disk.
Backup is not a one-time event — it is an ongoing, scheduled activity that runs continuously in the background of well-managed systems, whether daily, hourly, or in real time for critical data. Data Recovery, on the other hand, is used reactively — the moment data loss is discovered, whether that is immediately after an accidental deletion or days later when a corrupted file is first opened. The gap between when data is lost and when it is noticed is one of the most important factors in how successful a recovery attempt will be.
Day-to-Day Example: Cloud photo backup on a smartphone runs quietly every time the phone is charging and connected to Wi-Fi — you never see it happening. Data recovery, by contrast, is used the moment you realize you accidentally deleted an entire photo album and need it back immediately.
End users — students, employees, business owners — rely on backup and recovery every day, often without realizing it, simply by using cloud-synced apps or clicking 'Restore' after a mistake. IT Administrators and Backup Engineers are responsible for designing, scheduling, monitoring, and testing backup strategies within organizations to ensure compliance and reliability. Software companies — such as Veeam, Acronis, Veritas, and the built-in backup tools from Microsoft, Apple, and Google — build the tools that make backup and recovery possible, while Data Recovery Specialists handle the more advanced cases of physically damaged or severely corrupted storage devices.
[ Diagram ]
Fig 1.1 — The Backup and Data Recovery Cycle
Just as an Operating System performs multiple core functions, a backup strategy relies on several distinct backup methods, each suited to a different balance of speed, storage space, and recovery convenience. Understanding these methods is the foundation of designing any reliable backup plan.

A Full Backup copies every single selected file and folder in its entirety, every time the backup job runs, regardless of whether the data has changed since the previous backup. It is the simplest and most complete method, and because every backup is a full, independent copy, restoring data is fast and straightforward — but it consumes the most storage space and takes the longest time to complete.
Day-to-Day Example: Copying your entire 'Documents' folder onto an external hard drive every single Sunday, regardless of how many files actually changed during the week, is a full backup.
An Incremental Backup copies only the data that has changed since the last backup of any type (full or incremental), making it the fastest method and the most storage-efficient. However, restoring data requires the last full backup plus every incremental backup made since then, applied in the correct order, which makes recovery slightly slower and more complex.
A Differential Backup copies all the data that has changed since the last full backup (not since the last backup of any type). This makes each differential backup progressively larger over time, but restoring is simpler than incremental backup, since only the last full backup and the latest differential backup are needed.
A Mirror Backup creates an exact, real-time replica of the source data at the destination, with no compression and no historical versions — if a file is deleted from the source, it is also removed from the mirror. This provides instant access to an identical copy but offers no protection against accidental deletion, since the deletion is mirrored too.
Cloud Backup transmits data over the internet to be stored on a remote provider's servers (such as Google Drive, Dropbox, or AWS), removing the need for physical backup hardware on-site and protecting data even if the entire local location is destroyed. It depends on a stable internet connection and ongoing subscription costs, but offers excellent geographic redundancy.
Day-to-Day Example: A photographer who uploads every wedding shoot to Google Photos and Dropbox as soon as she gets home is using cloud backup — even if her laptop and external drive are both stolen the same night, her photos remain safe on remote servers.
A Snapshot Backup captures the exact state of an entire system, disk, or virtual machine at one specific point in time, including the operating system, settings, and running applications, allowing the whole environment to be rolled back instantly. Snapshots are common in virtualization and databases where a full, consistent 'point-in-time' image is more useful than individual file copies.
This section covers the key terminology every student must understand clearly before attempting revision or an interview on this topic. Each term is explained in detail with a simple example so the concept sticks.
RPO (Recovery Point Objective)
RPO is the maximum amount of data, measured in time, that an organization can afford to lose during an incident — in other words, how far back the most recent usable backup must be. It directly determines how frequently backups need to be taken.
Day-to-Day Example: If a company's RPO is 1 hour, it must back up its database at least every hour, because losing more than an hour's worth of transactions would be unacceptable.
RTO (Recovery Time Objective)
RTO is the maximum acceptable amount of time a system or service can remain down after a failure before it must be restored and operational again. It measures the speed of recovery, not the freshness of the data.
Day-to-Day Example: An e-commerce website with an RTO of 15 minutes must have its systems back online within 15 minutes of any outage, or it starts losing significant sales and customer trust.
3-2-1 Backup Rule
The 3-2-1 rule is a widely recommended backup strategy stating that you should keep at least 3 total copies of your data, store them on 2 different types of storage media, and keep 1 copy off-site, away from the primary location, to protect against site-wide disasters.
Day-to-Day Example: Keeping your thesis on your laptop, on an external hard drive, and also uploaded to cloud storage follows the 3-2-1 rule perfectly.
RAID (Redundant Array of Independent Disks)
RAID is a data storage technology that combines multiple physical disk drives into a single logical unit to improve performance, provide redundancy, or both. Different RAID levels (0, 1, 5, 6, 10) offer different trade-offs between speed, storage efficiency, and fault tolerance.
Day-to-Day Example: A video editing studio using RAID 5 across four disks can continue working even if one disk suddenly fails, because the data can be rebuilt from the remaining disks.
Disaster Recovery Plan (DRP)
A Disaster Recovery Plan is a formal, documented set of procedures an organization follows to recover its IT infrastructure and data after a catastrophic event such as a fire, cyberattack, or natural disaster, ensuring business operations can resume within a defined timeframe.
Day-to-Day Example: A bank's disaster recovery plan might specify that if its main data center goes offline, all operations automatically switch to a backup data center in another city within minutes.
Data Integrity / Checksum
Data Integrity refers to the accuracy and consistency of data over its lifecycle, ensuring it has not been altered or corrupted. A Checksum is a small calculated value derived from a file's contents, used to verify after copying or transferring that the file is identical to the original and has not been corrupted.
Day-to-Day Example: When you download a large software installer, the website often provides a checksum value so you can verify your downloaded file is not corrupted or tampered with.
Versioning
Versioning is a backup feature that keeps multiple historical copies of the same file as it changes over time, allowing a user to restore not just the most recent version, but any earlier saved version as well.
Day-to-Day Example: Google Docs' 'Version History' feature, which lets you scroll back and restore how a document looked an hour ago or a week ago, is a real-world example of versioning.
Cold, Warm, and Hot Sites
These are categories of backup disaster-recovery facilities distinguished by how quickly they can take over operations: a Cold Site has only basic infrastructure and takes the longest to activate; a Warm Site has some hardware and partially updated data ready to go; and a Hot Site is a fully operational, continuously synchronized duplicate that can take over almost instantly.
Day-to-Day Example: A stock exchange, where even a few seconds of downtime causes huge losses, uses a Hot Site that mirrors its primary systems live, so trading can continue instantly if the main site fails.
Deduplication
Data Deduplication is a technique that eliminates redundant copies of identical data blocks within a backup, storing only one unique copy and referencing it wherever it repeats, significantly reducing the storage space a backup consumes.
Day-to-Day Example: If 50 employees each have an identical copy of the same company policy PDF in their backed-up folders, deduplication ensures the backup storage only holds one actual copy of that file.
Encryption at Rest
Encryption at Rest refers to encrypting backup data while it is stored, so that even if the backup medium is stolen or accessed without authorization, the data remains unreadable without the correct decryption key.
Day-to-Day Example: A hospital encrypting all of its patient-record backups ensures that even if a backup hard drive is physically stolen, the sensitive medical data on it cannot be read by the thief.
Data recovery follows a careful, methodical sequence of steps to maximize the chances of retrieving lost or corrupted data without causing further damage. Understanding this process helps in reacting correctly the moment data loss is discovered, rather than making it worse through panic-driven actions.

Fig 4.1 — Step-by-step Data Recovery Process
Just as a running program moves through defined process states, a backup job moves through a well-defined life cycle each time it runs, managed by the backup software's scheduler. Understanding these states helps in monitoring and troubleshooting backup systems.
| State | Description |
|---|---|
| Scheduled | The backup job is queued to run at a specific time or trigger, but has not started yet. |
| Running | The backup software is actively reading source data and writing it to the destination. |
| Verifying | The completed backup is checked against a checksum or comparison to confirm it copied correctly. |
| Completed | The backup has finished successfully and is available for future restoration. |
| Failed | The backup job stopped due to an error (e.g., insufficient space, network failure) and needs attention or a retry. |
Day-to-Day Example: Think of a backup job like a delivery order: 'Scheduled' is the order being placed, 'Running' is the courier actually carrying the package, 'Verifying' is the receiver checking the package is undamaged, 'Completed' is a successful delivery, and 'Failed' is when the delivery could not be completed and must be attempted again.

Fig 5.1 — Backup Job Life Cycle Diagram
Backup data has to be stored somewhere, and over time several distinct types of backup storage systems have emerged, each suited to different budgets, speed requirements, and levels of protection.
| Storage Type | Definition & Use Case | Simple Example |
|---|---|---|
| Local/Direct-Attached Backup | Backup stored on a drive physically connected to the source device; fast but vulnerable to local disasters. | External USB hard drive backing up a personal laptop |
| NAS (Network-Attached Storage) | A dedicated storage device connected to a local network, backing up multiple devices centrally. | Office NAS box backing up every employee's computer |
| Cloud Backup | Data sent over the internet to a remote provider's data centers, offering strong off-site protection. | Google Drive, Dropbox, AWS S3 |
| Tape Backup | Data written to magnetic tape cartridges; very cheap per gigabyte and ideal for long-term archival. | Large enterprises archiving years of financial records |
| Hybrid Backup | Combines local backup (for fast recovery) with cloud backup (for off-site disaster protection). | A business backing up locally each night and syncing to the cloud weekly |
Comparison-based questions are very common in exams and interviews. These tables summarize the most important distinctions students must remember clearly for revision.
| Basis | Full Backup | Incremental Backup | Differential Backup |
|---|---|---|---|
| What is copied | Everything, every time | Only changes since the last backup of any kind | Only changes since the last full backup |
| Backup Speed | Slowest | Fastest | Moderate |
| Storage Needed | Highest | Lowest | Grows over time |
| Restore Speed | Fastest (single copy) | Slowest (needs full + all increments) | Moderate (needs full + last differential) |
| Best For | Small datasets, weekly baseline | Frequent, storage-limited backups | Balance of speed and easy restore |
| Basis | Backup | Data Recovery | Disaster Recovery |
|---|---|---|---|
| Core Idea | Proactively copying data before loss happens | Reactively retrieving data after it is lost | Restoring entire IT operations after a major event |
| Scope | Files, folders, databases | Files, folders, or a damaged drive | Whole systems, applications, and infrastructure |
| Timing | Ongoing, scheduled | Immediately after loss is discovered | Immediately after a catastrophic event |
| Example | Nightly backup of a database | Undeleting an accidentally removed folder | Failing over to a backup data center after a fire |
| RAID Level | Core Idea | Fault Tolerance | Typical Use Case |
|---|---|---|---|
| RAID 0 | Splits (stripes) data across disks for maximum speed. | None — one disk failure loses all data | High-speed video editing scratch disks |
| RAID 1 | Duplicates (mirrors) the same data across two disks. | High — survives one disk failure | Small business file servers |
| RAID 5 | Stripes data with distributed parity across 3+ disks. | Survives one disk failure | General-purpose office/enterprise servers |
| RAID 6 | Like RAID 5 but with double parity across 4+ disks. | Survives two disk failures | Large storage arrays needing extra safety |
| RAID 10 | Combines mirroring and striping across 4+ disks. | High — survives multiple failures (conditions apply) | High-performance databases |
| Basis | Cloud Backup | Local Backup | Hybrid Backup |
|---|---|---|---|
| Speed of Restore | Depends on internet speed | Very fast (direct connection) | Fast for recent data, cloud for older/off-site |
| Protection from Site Disaster | Excellent — data stored off-site | Poor — same location as source | Excellent — combines both strengths |
| Ongoing Cost | Subscription-based, scales with data | One-time hardware cost | Both hardware and subscription costs |
| Best For | Individuals, small teams, remote backup | Fast recovery of recent data | Organizations wanting speed and safety |
Windows, macOS, and Linux each ship with (or commonly use) different native backup approaches, reflecting the same platform philosophies seen across their operating systems more broadly.
| Basis | Windows (File History / Backup) | macOS (Time Machine) | Linux (rsync / Timeshift) |
|---|---|---|---|
| Built-in Tool | File History, Windows Backup | Time Machine | No single default; rsync, Timeshift, Bacula commonly used |
| Ease of Use | Beginner-friendly GUI setup | Extremely simple, near-automatic | Requires command-line comfort for full control |
| Versioning | Yes, keeps file history over time | Yes, hourly/daily/weekly snapshots | Yes, depending on chosen tool and configuration |
| Typical Destination | External drive or OneDrive | External drive or Time Capsule | External drive, NAS, or remote server via SSH |
| Common Use Case | Home & office users | Apple ecosystem users, creative professionals | Server admins, developers, self-hosted setups |
These questions test your practical understanding of the concepts covered above. Try answering them yourself first, then check the given answer and reasoning.
Q1. Every night your company copies only the files that changed that day onto a backup server, and on Sundays it takes a complete copy of everything. What backup strategy is being used, and why?
Answer: This is a combination of Full Backup (on Sunday) and Incremental Backup (on weekdays).
Why / Reason: Taking a full backup weekly establishes a complete baseline, while incremental backups on other days save time and storage by copying only what changed since the previous backup — a very common and efficient real-world strategy.
Q2. A hard disk in a server suddenly fails, but the server keeps running normally without any data loss because the missing disk's data is automatically rebuilt from the remaining disks. What technology explains this?
Answer: RAID (specifically a fault-tolerant level such as RAID 1, 5, 6, or 10).
Why / Reason: RAID combines multiple physical disks so that if one fails, the data can be reconstructed from redundancy (mirroring or parity) stored across the other disks, allowing operations to continue uninterrupted.
Q3. You accidentally deleted an important folder five minutes ago and haven't used the laptop since. What is the single most important action to take before attempting recovery?
Answer: Stop using the device immediately and avoid writing any new data to that drive.
Why / Reason: Deleted files often remain physically recoverable on the disk until the space they occupied is overwritten by new data; continuing to use the device risks permanently destroying the recoverable file fragments.
Q4. A company's disaster recovery plan states that if its main office is destroyed by fire, operations must resume at a backup data center within 10 minutes. What term describes this 10-minute target?
Answer: RTO (Recovery Time Objective).
Why / Reason: RTO specifically measures the maximum acceptable downtime after a failure before systems must be operational again — in this case, the company has defined a very aggressive RTO of 10 minutes.
Q5. A hospital's backup policy states it can never lose more than 15 minutes of patient record updates, no matter what happens. What term describes this requirement, and what must the hospital do to meet it?
Answer: This describes the RPO (Recovery Point Objective) of 15 minutes; the hospital must back up its patient records at least every 15 minutes.
Why / Reason: RPO defines how much data loss (measured in time) is tolerable. A 15-minute RPO requires backups frequent enough that no more than 15 minutes of data would ever be missing after a failure.
Q6. An employee keeps a copy of an important spreadsheet on their laptop, on an office external hard drive, and also on a cloud storage account. What backup principle does this follow?
Answer: The 3-2-1 Backup Rule.
Why / Reason: There are 3 total copies of the data, stored on 2 different media types (laptop disk and external hard drive), with 1 copy kept off-site (the cloud account) — matching the 3-2-1 rule exactly.
Q7. A stock trading platform cannot afford even a few seconds of downtime, so it maintains a fully live, continuously synced duplicate of its entire system in a second location, ready to take over instantly. What is this type of facility called?
Answer: A Hot Site.
Why / Reason: A hot site is a fully operational, real-time mirror of the primary system that can take over almost instantly, which is essential for systems like stock trading platforms where even brief downtime is unacceptable.
1. What is the difference between backup and data recovery?
Backup is the proactive process of copying data before anything goes wrong, while data recovery is the reactive process of retrieving data after it has already been lost, corrupted, or become inaccessible.
2. What are the main types of backup?
Full, Incremental, Differential, Mirror, Cloud, and Snapshot backups are the main types, each offering a different trade-off between speed, storage use, and restore convenience.
3. What is RPO and RTO?
RPO (Recovery Point Objective) is the maximum tolerable data loss measured in time, while RTO (Recovery Time Objective) is the maximum tolerable downtime before systems must be restored and operational.
4. What is the 3-2-1 backup rule?
It recommends keeping at least 3 copies of data, on 2 different storage media types, with 1 copy stored off-site, to protect against both device failure and site-wide disasters.
5. What is RAID, and why is it used?
RAID combines multiple physical disks into one logical unit to improve performance, provide redundancy, or both, so that data can survive individual disk failures and/or be accessed faster.
6. What is the difference between incremental and differential backup?
Incremental backup copies only data changed since the last backup of any type, making it fastest but slower to restore; differential backup copies all data changed since the last full backup, making restores simpler but each backup larger over time.
7. What is a Disaster Recovery Plan?
A Disaster Recovery Plan is a documented set of procedures an organization follows to restore its IT systems and data after a catastrophic event, ensuring operations can resume within a defined time.
8. What is data deduplication?
Deduplication is a technique that stores only one copy of identical data blocks and references them wherever they repeat, significantly reducing the storage space required for backups.
9. Why is encryption important in backups?
Encryption ensures that even if a backup medium is stolen or accessed without authorization, the stored data remains unreadable without the correct decryption key, protecting sensitive information.
10. What should you do first if you accidentally delete an important file?
Stop using the affected device immediately to avoid overwriting the deleted file's data, then check for an existing backup before attempting any recovery software.
1. A client's server crashed and the most recent full backup is a week old, with daily incrementals since then. Walk me through how you would restore the data.
I would first restore the most recent full backup as the baseline, and then apply each daily incremental backup in the correct chronological order since that full backup, ending with the most recent one, to bring the data up to the latest possible point before the crash.
2. Your company wants to reduce backup storage costs without increasing the risk of data loss. What would you suggest?
I would suggest a combination of deduplication (to avoid storing repeated data), incremental backups (to avoid re-copying unchanged data), and a tiered strategy — keeping recent backups on fast local storage and older backups on cheaper archival storage like tape or cold cloud storage.
3. How would you explain RPO and RTO to a non-technical manager using a simple analogy?
RPO is like asking 'how much recent work am I willing to redo if something goes wrong right now?' — the shorter the RPO, the more often we must save. RTO is like asking 'how long can we afford to be completely stopped?' — the shorter the RTO, the faster and more expensive our recovery plan needs to be.
4. A hard disk is physically clicking and won't mount. What should NOT be done, and what is the correct next step?
The disk should not be repeatedly powered on and off, and no recovery software should be run directly on it, since a physically failing disk can suffer further damage with each use. The correct step is to stop using it immediately and send it to a professional data recovery lab with proper cleanroom equipment.
5. How would you design a backup strategy for a small business with a limited budget?
I would recommend a hybrid approach following the 3-2-1 rule: a daily incremental local backup to a NAS or external drive for fast restores, combined with a weekly full backup synced to an affordable cloud storage service for off-site protection, keeping both cost and recovery speed balanced.