Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Easy

A multinational corporation has a strict data residency requirement that mandates all data classified as 'Confidential' must reside only in specific geographical regions (e.g., EU-West-1, US-East-2). They need to build a custom compliance policy in Prisma Cloud to enforce this. Which RQL query component would be MOST critical for filtering resources based on their geographical location?

  1. AresourceType
  2. BaccountId
  3. Ctags
  4. Dregion
Show answer & explanation

Correct answer: D. region

The 'region' attribute in RQL directly corresponds to the geographical location where a cloud resource is deployed. This is the most critical component for filtering resources based on data residency requirements.

Why the other options are wrong

  • A. resourceType identifies the kind of resource (e.g., EC2, S3), not its location.
  • B. accountId identifies the cloud account, not the specific geographical region within that account.
  • C. tags can be used for custom metadata, but 'region' is a built-in, definitive attribute for geographical location.

RQL Region Attribute

A key attribute in Prisma Cloud's Resource Query Language (RQL) used to filter cloud resources based on their deployed geographical region.

  • Essential for enforcing data residency and geographical compliance.
  • Standardized across supported cloud providers (e.g., AWS regions, Azure locations).
  • Used in the 'where' clause of RQL queries.

Memory trick: To filter by location, use the 'region' attribute, it's the geographic key.

More Cloud Security Posture Management (CSPM) questions