Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A financial services organization uses Prisma Cloud to monitor its AWS environment. Due to strict regulatory requirements, they need to ensure that all S3 buckets storing sensitive customer data are encrypted at rest using KMS keys and are not publicly accessible. Which type of policy in Prisma Cloud would be most effective for continuously enforcing these specific requirements?

  1. ABuilt-in Compliance Policies
  2. BCustom Policies (RQL)
  3. CAlert Suppression Policies
  4. DAutomated Remediation Policies
Show answer & explanation

Correct answer: B. Custom Policies (RQL)

While built-in policies exist, specific requirements like 'S3 buckets with sensitive data encrypted using KMS keys AND not publicly accessible' often require the granular control and specificity offered by Custom Policies written in RQL (Resource Query Language). Automated remediation would act on these policies, and suppression policies are for alerts, not enforcement.

Why the other options are wrong

  • A. Built-in policies might cover parts, but often lack the specific combination of conditions required for unique organizational needs.
  • C. Alert Suppression policies reduce alert noise; they do not define or enforce security posture.
  • D. Automated Remediation policies act as a response to policy violations, they are not the policy definition itself.

Prisma Cloud Custom Policies (RQL)

Prisma Cloud's mechanism to define highly specific security and compliance rules using Resource Query Language (RQL).

  • Uses RQL for granular control.
  • Addresses unique organizational compliance needs.
  • Can combine multiple conditions and resource types.

Memory trick: Custom RQL policies are like tailored suits for your cloud security.

More Cloud Security Posture Management (CSPM) questions