Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
A security analyst is reviewing the asset inventory in Prisma Cloud for their GCP environment. They need to quickly find all Compute Engine instances that have external IP addresses assigned and are located in the 'us-central1' region. Which RQL query would accomplish this task?
- Aconfig from gcp.compute.instance where network.privateIp = false and region = 'us-central1'
- Bconfig from gcp.compute.instance where network.externalIp and region = 'us-central1'
- Cconfig from gcp.compute.instance where network.publicIp = true and region = 'us-central1'
- Dconfig from gcp.compute.instance where externalIp is not null and region = 'us-central1'
Show answer & explanationAnswer & explanation
Correct answer: B. config from gcp.compute.instance where network.externalIp and region = 'us-central1'
In Prisma Cloud's RQL for GCP Compute Engine instances, the presence of an external IP address is typically represented by the `network.externalIp` attribute. When this attribute exists (i.e., is not null or explicitly defined), it indicates an external IP. The `and region = 'us-central1'` correctly filters by region.
Why the other options are wrong
- A. Filtering by `network.privateIp = false` does not guarantee the presence of an external IP; an instance might have no public/external IP and only a private IP, or no IP at all.
- C. While `network.publicIp` might be intuitive, `network.externalIp` is the more common and accurate RQL attribute for GCP external IPs.
- D. Using `externalIp is not null` is a valid RQL construct, but `network.externalIp` is the more direct and standard attribute for this check in GCP RQL.
RQL for GCP External IPs
In Prisma Cloud's Resource Query Language (RQL), the `network.externalIp` attribute is used to identify GCP Compute Engine instances that have external (public) IP addresses assigned, allowing for filtering based on public exposure.
- Identifies public IP presence on GCP instances.
- Part of the `network` object for instances.
- Crucial for assessing internet exposure.
Memory trick: For GCP public, think 'externalIp' in the 'network'.