Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A security engineer is using Prisma Cloud to implement a new compliance standard for their organization, which requires specific tagging conventions for all cloud resources. They need to identify all resources that are missing a 'Department' tag or have an invalid value (e.g., 'Unknown' or 'N/A'). Which RQL query most efficiently achieves this?

  1. Aconfig from cloud.resource where tags.Department is null OR tags.Department = 'Unknown' OR tags.Department = 'N/A'
  2. Bconfig from cloud.resource where api.name = '*' AND (tags.Department does not exist OR tags.Department IN ('Unknown', 'N/A'))
  3. Cconfig from cloud.resource where api.name = '*' AND tags.Department doesn't exist OR tags.Department IN ('Unknown', 'N/A')
  4. Dconfig from cloud.resource where tags.Department does not exist AND tags.Department IN ('Unknown', 'N/A')
Show answer & explanation

Correct answer: B. config from cloud.resource where api.name = '*' AND (tags.Department does not exist OR tags.Department IN ('Unknown', 'N/A'))

The RQL query needs to correctly combine conditions for missing tags and invalid tag values using logical operators. Option B correctly uses 'does not exist' for missing tags and 'IN' for multiple invalid values, combined with parentheses for proper logical grouping.

Why the other options are wrong

  • A. Uses `is null` which is not the correct RQL operator for a missing tag; `IN` is more efficient than multiple `OR` statements for specific values.
  • C. Uses 'doesn't exist' which is not valid RQL syntax; also lacks proper grouping for OR conditions.
  • D. Uses `AND` between `does not exist` and `IN`, which would result in an empty set as a tag cannot simultaneously not exist and have a value.

RQL Tag Filtering

Resource Query Language (RQL) in Prisma Cloud allows filtering cloud resources based on their tags, including checking for existence and specific values.

  • Use `tags.<tag_key> does not exist` to find resources missing a specific tag.
  • Use `tags.<tag_key> IN ('value1', 'value2')` to find resources with specific tag values.
  • Logical operators (`AND`, `OR`) and parentheses are crucial for combining conditions.

Memory trick: Remember 'Tag Exists, Value Lists, Logic Connects' for RQL tag queries.

More Cloud Security Posture Management (CSPM) questions