Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard

A global organization is utilizing Prisma Cloud for its multi-cloud environment. They have a strict compliance requirement to ensure that all S3 buckets storing sensitive customer data are encrypted with Server-Side Encryption with AWS Key Management Service (SSE-KMS) and that the KMS keys used are customer-managed (CMK), not AWS-managed (AMK). Which RQL query would accurately identify S3 buckets that are NOT encrypted with SSE-KMS using a customer-managed key?

  1. Aconfig from aws.s3.bucket where encryption.type = 'AES256'
  2. Bconfig from aws.s3.bucket where encryption.type != 'aws:kms' or not encryption.kmsKeyId starts with 'arn:aws:kms:' or encryption.kmsKeyId contains ':alias/aws/'
  3. Cconfig from aws.s3.bucket where encryption.type = 'aws:kms' and encryption.kmsKeyId starts with 'arn:aws:kms:' and not encryption.kmsKeyId ends with ':alias/aws/'
  4. Dconfig from aws.s3.bucket where encryption.type != 'aws:kms' or encryption.kmsKeyId ends with ':alias/aws/'
Show answer & explanation

Correct answer: B. config from aws.s3.bucket where encryption.type != 'aws:kms' or not encryption.kmsKeyId starts with 'arn:aws:kms:' or encryption.kmsKeyId contains ':alias/aws/'

The requirement is to find buckets NOT encrypted with SSE-KMS using a customer-managed key. This means we are looking for buckets where either the encryption type is not 'aws:kms' OR the KMS key ID does not start with 'arn:aws:kms:' (indicating it's not a KMS key) OR it's an AWS-managed key (indicated by ':alias/aws/'). Option D correctly captures these conditions using OR logic.

Why the other options are wrong

  • A. This query identifies buckets encrypted with AES256, which is not SSE-KMS and doesn't consider CMK vs. AMK.
  • C. This query identifies buckets that ARE encrypted with SSE-KMS using a customer-managed key. The question asks for buckets that are NOT.
  • D. This query would identify buckets not encrypted with SSE-KMS OR if the KMS key ID ends with ':alias/aws/', which is close, but 'ends with' might not cover all AMK scenarios comprehensively and the 'not starts with arn:aws:kms:' is missing for a full check.

RQL for SSE-KMS CMK

Resource Query Language (RQL) queries in Prisma Cloud can be used to identify S3 buckets based on their encryption configuration, specifically differentiating between Server-Side Encryption with AWS KMS (SSE-KMS) using customer-managed keys (CMKs) versus AWS-managed keys (AMKs).

  • SSE-KMS uses 'aws:kms' as encryption type.
  • CMKs have a specific ARN format and do not contain ':alias/aws/'.
  • AMKs often contain ':alias/aws/' in their key ID or are implicitly AWS managed.

Memory trick: To find the 'NOT', combine the 'OR' conditions.

More Cloud Security Posture Management (CSPM) questions