Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
A security engineer is using Prisma Cloud to implement a new compliance standard for their organization, which requires specific tagging conventions for all cloud resources. They need to identify all resources that are missing a 'Department' tag or have an invalid value (e.g., 'Unknown' or 'N/A'). Which RQL query most efficiently achieves this?
- Aconfig from cloud.resource where tags.Department is null OR tags.Department = 'Unknown' OR tags.Department = 'N/A'
- Bconfig from cloud.resource where api.name = '*' AND (tags.Department does not exist OR tags.Department IN ('Unknown', 'N/A'))
- Cconfig from cloud.resource where api.name = '*' AND tags.Department doesn't exist OR tags.Department IN ('Unknown', 'N/A')
- Dconfig from cloud.resource where tags.Department does not exist AND tags.Department IN ('Unknown', 'N/A')
Show answer & explanationAnswer & explanation
Correct answer: B. config from cloud.resource where api.name = '*' AND (tags.Department does not exist OR tags.Department IN ('Unknown', 'N/A'))
The RQL query needs to correctly combine conditions for missing tags and invalid tag values using logical operators. Option B correctly uses 'does not exist' for missing tags and 'IN' for multiple invalid values, combined with parentheses for proper logical grouping.
Why the other options are wrong
- A. Uses `is null` which is not the correct RQL operator for a missing tag; `IN` is more efficient than multiple `OR` statements for specific values.
- C. Uses 'doesn't exist' which is not valid RQL syntax; also lacks proper grouping for OR conditions.
- D. Uses `AND` between `does not exist` and `IN`, which would result in an empty set as a tag cannot simultaneously not exist and have a value.
RQL Tag Filtering
Resource Query Language (RQL) in Prisma Cloud allows filtering cloud resources based on their tags, including checking for existence and specific values.
- Use `tags.<tag_key> does not exist` to find resources missing a specific tag.
- Use `tags.<tag_key> IN ('value1', 'value2')` to find resources with specific tag values.
- Logical operators (`AND`, `OR`) and parentheses are crucial for combining conditions.
Memory trick: Remember 'Tag Exists, Value Lists, Logic Connects' for RQL tag queries.