A security analyst is investigating a surge in 'Publicly Exposed Storage' alerts from Prisma Cloud for their Azure environment. They want to quickly identify all Azure Storage Accounts that have public access enabled and are not encrypted at rest. Which RQL query should they use?
- Aconfig from cloud.resource where resourceType = 'azure.storage.storageAccount' and properties.publicNetworkAccess = 'Enabled' and properties.encryption.keySource != 'Microsoft.Keyvault'
- Bconfig from cloud.resource where resourceType = 'azure.storage.storageAccount' and properties.publicNetworkAccess = 'Enabled' and properties.encryption.keySource = 'Microsoft.Storage'
- Cconfig from cloud.resource where resourceType = 'azure.storage.storageAccount' and properties.publicNetworkAccess = 'Enabled' or properties.encryption.keySource != 'Microsoft.Keyvault'
- Dconfig from cloud.resource where resourceType = 'azure.storage.storageAccount' and properties.publicNetworkAccess = 'Enabled' and not properties.encryption
Show answer & explanationAnswer & explanation
Correct answer: A. config from cloud.resource where resourceType = 'azure.storage.storageAccount' and properties.publicNetworkAccess = 'Enabled' and properties.encryption.keySource != 'Microsoft.Keyvault'
The analyst needs to find Azure Storage Accounts that are both publicly accessible AND not encrypted with customer-managed keys (which implies default Microsoft-managed encryption or no encryption configured). Option B correctly uses 'and' to combine these two conditions and checks for the absence of 'Microsoft.Keyvault' as the key source.
Why the other options are wrong
- B. Checks for 'Microsoft.Storage' as the key source, which means Microsoft-managed encryption, not necessarily unencrypted or lacking customer-managed encryption.
- C. Uses 'or' between the public access and encryption conditions, which would return accounts that are either publicly accessible OR not encrypted with Key Vault, not necessarily both.
- D. The 'not properties.encryption' check is too broad and might not correctly identify accounts lacking customer-managed encryption while still having default Microsoft-managed encryption.
RQL for Azure Storage Account Security
RQL queries can target specific Azure resource types like 'azure.storage.storageAccount' and inspect their properties to identify security misconfigurations, such as public access and encryption status.
- Resource Type: 'azure.storage.storageAccount'.
- Public Access Property: 'properties.publicNetworkAccess'.
- Encryption Key Source Property: 'properties.encryption.keySource'.
Memory trick: Azure Storage security: Public + no KeyVault = Red flag!