Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard
A security engineer is using Prisma Cloud to identify all EC2 instances across their AWS, Azure, and GCP environments that are running an operating system from the 'Windows' family and have not been patched in the last 30 days. This requires a custom policy. Which type of policy in Prisma Cloud is best suited for this cross-cloud, attribute-based detection?
- ACustom Policy (RQL based)
- BNetwork Policy
- CCompliance Policy
- DVulnerability Policy
Show answer & explanationAnswer & explanation
Correct answer: A. Custom Policy (RQL based)
A Custom Policy, defined using Resource Query Language (RQL), is the most flexible and powerful way to create a policy that spans multiple cloud providers and filters resources based on specific attributes like OS family and last patch date, which might not be covered by a pre-defined compliance or vulnerability policy in the exact way required.
Why the other options are wrong
- B. Network policies focus on network connectivity and traffic rules, not resource attributes like OS family or patch date.
- C. Compliance policies are typically pre-defined standards; while you can map custom policies to them, creating the specific logic requires a custom RQL policy first.
- D. Vulnerability policies focus on CVEs and known vulnerabilities, but combining OS family and patch date across multiple clouds for a custom definition is best done via RQL.
Prisma Cloud Custom Policy (RQL)
User-defined policies created using Resource Query Language (RQL) to detect specific configurations or misconfigurations across cloud environments.
- Provides maximum flexibility for detection.
- Supports multi-cloud attribute-based filtering.
- Can be integrated into compliance standards and automated remediation.
Memory trick: When it's 'custom' logic, you need a 'Custom Policy with RQL'.