Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Hard

A global organization uses Prisma Cloud to manage security posture across AWS, Azure, and GCP. They have a critical requirement to ensure that all sensitive data stored in cloud storage services (S3, Blob Storage, Cloud Storage) is encrypted using customer-managed encryption keys (CMEK) rather than platform-managed keys. How can Prisma Cloud best help them enforce this specific encryption standard across all supported cloud providers?

  1. ABy creating a custom policy using RQL that queries for storage resources not using CMEK across all cloud providers.
  2. BBy enabling automated remediation for 'unencrypted storage' alerts, which covers CMEK requirement by default.
  3. CBy utilizing a single, built-in compliance policy that automatically detects and remediates non-CMEK encryption.
  4. DBy manually reviewing each storage account in the asset inventory for its encryption configuration.
Show answer & explanation

Correct answer: A. By creating a custom policy using RQL that queries for storage resources not using CMEK across all cloud providers.

Enforcing a specific encryption standard like CMEK across multiple cloud providers requires a custom policy. While built-in policies might cover basic encryption, the distinction between platform-managed and customer-managed keys, and the need to apply this across various cloud storage types (S3, Blob, Cloud Storage), necessitates the flexibility of RQL to create a precise custom policy. Manual review is not scalable, and 'unencrypted storage' alerts typically don't differentiate between key types by default.

Why the other options are wrong

  • B. 'Unencrypted storage' alerts are usually for the absence of *any* encryption, not the specific type of key used (CMEK vs. platform-managed).
  • C. Built-in policies often don't have the granularity to distinguish between platform-managed and customer-managed encryption keys across multiple cloud providers.
  • D. Manual review is impractical and prone to error in a large, dynamic multi-cloud environment.

Multi-Cloud Custom Policy (CMEK)

A Prisma Cloud custom policy, defined using RQL, to enforce specific encryption standards like Customer-Managed Encryption Keys (CMEK) across diverse storage services in multiple cloud environments.

  • Addresses granular, multi-cloud requirements.
  • Differentiates between encryption key types (CMEK vs. default).
  • Leverages RQL for precise querying across S3, Blob, Cloud Storage.

Memory trick: RQL is the Rosetta Stone for multi-cloud encryption standards.

More Cloud Security Posture Management (CSPM) questions