Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A financial institution uses Prisma Cloud to enforce strict compliance with PCI DSS. They have identified a requirement to ensure all databases storing cardholder data (CHD) are encrypted at rest. How can a security engineer MOST effectively create a custom policy in Prisma Cloud to specifically check for unencrypted RDS instances tagged as 'DataClassification:PCI-DSS' across all connected AWS accounts?

  1. AUse a built-in compliance policy for PCI DSS and manually filter for RDS instances.
  2. BDevelop a serverless function to poll AWS for unencrypted RDS instances and send findings to Prisma Cloud via API.
  3. CUtilize RQL in a Custom Policy to query for 'config from cloud.resource where resourceType = 'aws_rds_db_instance' and tags.DataClassification = 'PCI-DSS' and encrypted = false'.
  4. DCreate a new alert rule in Alert Management to look for unencrypted RDS.
Show answer & explanation

Correct answer: C. Utilize RQL in a Custom Policy to query for 'config from cloud.resource where resourceType = 'aws_rds_db_instance' and tags.DataClassification = 'PCI-DSS' and encrypted = false'.

Custom Policies in Prisma Cloud allow organizations to define their own compliance checks using RQL (Resource Query Language). This enables precise targeting of specific resource types, tags, and configuration attributes across all monitored accounts, making it the most effective way to enforce a custom, tagged-based encryption policy.

Why the other options are wrong

  • A. Built-in policies might not be granular enough or allow specific tag filtering, requiring manual effort outside of continuous monitoring.
  • B. While possible, developing external functions is less efficient and doesn't leverage Prisma Cloud's native custom policy capabilities for continuous monitoring.
  • D. Alert rules are triggered by policies, not the mechanism for defining the policy logic itself.

Prisma Cloud Custom Policies

User-defined compliance rules in Prisma Cloud, crafted using RQL, to enforce specific security standards and organizational requirements.

  • Leverage RQL for powerful and flexible rule creation.
  • Can target specific resource types, tags, and configuration attributes.
  • Enable enforcement of unique organizational policies beyond built-in standards.

Memory trick: Craft your own rules with RQL, tag your resources, and encrypt your data.

More Cloud Security Posture Management (CSPM) questions