A global organization uses Prisma Cloud to manage security posture across AWS, Azure, and GCP. They have a critical requirement to ensure that all sensitive data stored in cloud storage services (S3, Blob Storage, Cloud Storage) is encrypted using customer-managed encryption keys (CMEK) rather than platform-managed keys. How can Prisma Cloud best help them enforce this specific encryption standard across all supported cloud providers?
- ABy creating a custom policy using RQL that queries for storage resources not using CMEK across all cloud providers.
- BBy enabling automated remediation for 'unencrypted storage' alerts, which covers CMEK requirement by default.
- CBy utilizing a single, built-in compliance policy that automatically detects and remediates non-CMEK encryption.
- DBy manually reviewing each storage account in the asset inventory for its encryption configuration.
Show answer & explanationAnswer & explanation
Correct answer: A. By creating a custom policy using RQL that queries for storage resources not using CMEK across all cloud providers.
Enforcing a specific encryption standard like CMEK across multiple cloud providers requires a custom policy. While built-in policies might cover basic encryption, the distinction between platform-managed and customer-managed keys, and the need to apply this across various cloud storage types (S3, Blob, Cloud Storage), necessitates the flexibility of RQL to create a precise custom policy. Manual review is not scalable, and 'unencrypted storage' alerts typically don't differentiate between key types by default.
Why the other options are wrong
- B. 'Unencrypted storage' alerts are usually for the absence of *any* encryption, not the specific type of key used (CMEK vs. platform-managed).
- C. Built-in policies often don't have the granularity to distinguish between platform-managed and customer-managed encryption keys across multiple cloud providers.
- D. Manual review is impractical and prone to error in a large, dynamic multi-cloud environment.
Multi-Cloud Custom Policy (CMEK)
A Prisma Cloud custom policy, defined using RQL, to enforce specific encryption standards like Customer-Managed Encryption Keys (CMEK) across diverse storage services in multiple cloud environments.
- Addresses granular, multi-cloud requirements.
- Differentiates between encryption key types (CMEK vs. default).
- Leverages RQL for precise querying across S3, Blob, Cloud Storage.
Memory trick: RQL is the Rosetta Stone for multi-cloud encryption standards.