There's a section in the administrator guide that covers parts of this:
https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/admin_guide/b_ise_admin_3_4/b_ISE_admin_maintain_monitor.html#ID312
You will only create a backup from the primary administration node, and you will only restore to the primary administration node.
After you restore the primary node, you need to re-synchronize secondary nodes to the primary.
Or alternatively you could also either remove and re-join the secondary node to the deployment to get the config sync from the restored primary.
If a secondary node fails, you can just re-deploy a new secondary, install certificates and re-join to the deployment, and it will sync config from the primary, so no backup/restore method is required here.
---
Please mark helpful answers & solutions
---