Function Description
The Cloud Security Center platform supports enabling data protection policies. All assets are protected at the daily level through scheduled snapshots. When it detects that security software has been uninstalled or there is a suspected ransomware risk, it immediately triggers a snapshot for data protection. When an anomaly is detected, it also persists the original scheduled protection files to prevent overwriting by malicious data.
Precautions
1. The data protection policy automatically creates snapshots for VMs every day. It is recommended to prioritize adding VMs for critical business to the policy, so that data can be quickly recovered when encountering serious security issues such as ransomware.
2. Generally, the policy only retains the latest 1 snapshot file. When serious security incidents such as malicious damage or suspected ransomware are detected, the latest snapshot file before the incident will be retained for 7 days.
3. In the data protection policy, there is a certain limit on the number of snapshots created per day:
- Hybrid volume: vm_num=(0.6(host_num-3)×4+12)×(capacity of a single SSD×0.5×number of SSD disks/480G). Note: If the storage capacities are heterogeneous (unequal), the minimum storage capacity shall prevail.
- All-flash volume: 2048
4. If the selected VM or consistency group already has an existing snapshot policy, it will be removed from the original policy and added to the current data protection policy.
5. VMs/consistency groups added to the data protection policy will have one snapshot created every day.
Prerequisites
The platform's snapshot policy has been set to intelligent mode. The data protection policy cannot be enabled in manual mode.
Operation Steps:
Step 1.Navigate to Security > aSecurity > Data Protection Policy, Add resource pools for which you want to enable the data protection policy
Only the VMs in the resource pool with data protection policy enabled can be added to the policy. The added VMs will be removed from the policy if the resource pool to which the VMs belong is removed from the table below.
Step 2.After enabling the function, navigate to Snapshot > Snapshot Policies. You can view two snapshot policies automatically generated by the Cloud Security Center. Their description is "Built-in Security Data Protection Policy" and they cannot be modified.
Step 3.Select VMs and consistency groups to add to the data protection policy, click Add Virtual Machine or Add Consistency Group, and add the virtual machine/consistency group to the data protection policy.