A global organization is utilizing Prisma Cloud for its multi-cloud environment. They have a strict compliance requirement to ensure that all S3 buckets storing sensitive customer data are encrypted with Server-Side Encryption with AWS Key Management Service (SSE-KMS) and that the KMS keys used are customer-managed (CMK), not AWS-managed (AMK). Which RQL query would accurately identify S3 buckets that are NOT encrypted with SSE-KMS using a customer-managed key?
- Aconfig from aws.s3.bucket where encryption.type = 'AES256'
- Bconfig from aws.s3.bucket where encryption.type != 'aws:kms' or not encryption.kmsKeyId starts with 'arn:aws:kms:' or encryption.kmsKeyId contains ':alias/aws/'
- Cconfig from aws.s3.bucket where encryption.type = 'aws:kms' and encryption.kmsKeyId starts with 'arn:aws:kms:' and not encryption.kmsKeyId ends with ':alias/aws/'
- Dconfig from aws.s3.bucket where encryption.type != 'aws:kms' or encryption.kmsKeyId ends with ':alias/aws/'
Show answer & explanationAnswer & explanation
Correct answer: B. config from aws.s3.bucket where encryption.type != 'aws:kms' or not encryption.kmsKeyId starts with 'arn:aws:kms:' or encryption.kmsKeyId contains ':alias/aws/'
The requirement is to find buckets NOT encrypted with SSE-KMS using a customer-managed key. This means we are looking for buckets where either the encryption type is not 'aws:kms' OR the KMS key ID does not start with 'arn:aws:kms:' (indicating it's not a KMS key) OR it's an AWS-managed key (indicated by ':alias/aws/'). Option D correctly captures these conditions using OR logic.
Why the other options are wrong
- A. This query identifies buckets encrypted with AES256, which is not SSE-KMS and doesn't consider CMK vs. AMK.
- C. This query identifies buckets that ARE encrypted with SSE-KMS using a customer-managed key. The question asks for buckets that are NOT.
- D. This query would identify buckets not encrypted with SSE-KMS OR if the KMS key ID ends with ':alias/aws/', which is close, but 'ends with' might not cover all AMK scenarios comprehensively and the 'not starts with arn:aws:kms:' is missing for a full check.
RQL for SSE-KMS CMK
Resource Query Language (RQL) queries in Prisma Cloud can be used to identify S3 buckets based on their encryption configuration, specifically differentiating between Server-Side Encryption with AWS KMS (SSE-KMS) using customer-managed keys (CMKs) versus AWS-managed keys (AMKs).
- SSE-KMS uses 'aws:kms' as encryption type.
- CMKs have a specific ARN format and do not contain ':alias/aws/'.
- AMKs often contain ':alias/aws/' in their key ID or are implicitly AWS managed.
Memory trick: To find the 'NOT', combine the 'OR' conditions.