Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Easy
A multinational corporation has a strict data residency requirement that mandates all data classified as 'Confidential' must reside only in specific geographical regions (e.g., EU-West-1, US-East-2). They need to build a custom compliance policy in Prisma Cloud to enforce this. Which RQL query component would be MOST critical for filtering resources based on their geographical location?
- AresourceType
- BaccountId
- Ctags
- Dregion
Show answer & explanationAnswer & explanation
Correct answer: D. region
The 'region' attribute in RQL directly corresponds to the geographical location where a cloud resource is deployed. This is the most critical component for filtering resources based on data residency requirements.
Why the other options are wrong
- A. resourceType identifies the kind of resource (e.g., EC2, S3), not its location.
- B. accountId identifies the cloud account, not the specific geographical region within that account.
- C. tags can be used for custom metadata, but 'region' is a built-in, definitive attribute for geographical location.
RQL Region Attribute
A key attribute in Prisma Cloud's Resource Query Language (RQL) used to filter cloud resources based on their deployed geographical region.
- Essential for enforcing data residency and geographical compliance.
- Standardized across supported cloud providers (e.g., AWS regions, Azure locations).
- Used in the 'where' clause of RQL queries.
Memory trick: To filter by location, use the 'region' attribute, it's the geographic key.