Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
A financial services organization uses Prisma Cloud to enforce strict data residency requirements. They have a policy stating that all S3 buckets storing customer financial data must reside in specific regions (e.g., 'us-east-1' or 'eu-west-1'). An auditor asks for a report showing all S3 buckets that violate this policy. Which RQL query would accurately identify these non-compliant buckets?
- Aconfig from cloud.resource where resource.type = 'aws_s3_bucket' and resource.region NOT IN ('us-east-1', 'eu-west-1')
- Bconfig from cloud.resource where resource.type = 'aws_s3_bucket' and resource.region NOT IN ('us-east-1') and resource.region NOT IN ('eu-west-1')
- Cconfig from cloud.resource where resource.type = 'aws_s3_bucket' and resource.region = 'us-east-1' or resource.region = 'eu-west-1'
- Dconfig from cloud.resource where resource.type = 'aws_s3_bucket' and resource.region != 'us-east-1' and resource.region != 'eu-west-1'
Show answer & explanationAnswer & explanation
Correct answer: A. config from cloud.resource where resource.type = 'aws_s3_bucket' and resource.region NOT IN ('us-east-1', 'eu-west-1')
To find buckets that are NOT in the allowed regions, the `NOT IN` operator is the most concise and accurate way to specify that the `resource.region` should not be present in the list of approved regions. Option A correctly uses `NOT IN ('us-east-1', 'eu-west-1')`.
Why the other options are wrong
- B. Uses `NOT IN` for individual regions, which is redundant and less efficient than a single `NOT IN` with a list.
- C. Uses 'or', which would find buckets that *are* in the allowed regions, directly opposite of the requirement.
- D. Uses `!=` with `and`, which is logically equivalent to `NOT IN` for two specific regions, but `NOT IN` is generally preferred for lists and is more readable.
RQL NOT IN Operator
A Resource Query Language (RQL) operator used to filter resources where a specific attribute's value is not present within a given list of values.
- Efficient for checking against multiple exclusions.
- Often used for compliance and data residency checks.
- Provides a concise way to express 'not equal to any of these'.
Memory trick: If it's NOT IN the allowed list, it's out!