Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium
A security engineer is tasked with configuring Prisma Cloud to identify all AWS S3 buckets that are publicly accessible AND are not encrypted with Server-Side Encryption with AWS Key Management Service (SSE-KMS). Which RQL query correctly identifies these resources?
- Aconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and not json.serverSideEncryption.type = 'aws:kms'
- Bconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true or json.serverSideEncryption.type != 'aws:kms'
- Cconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and json.serverSideEncryption.type = 'None'
- Dconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and json.serverSideEncryption.type != 'aws:kms'
Show answer & explanationAnswer & explanation
Correct answer: D. config from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and json.serverSideEncryption.type != 'aws:kms'
The query needs to identify S3 buckets that meet two conditions simultaneously: public accessibility AND lack of SSE-KMS encryption. The 'AND' logical operator correctly links these conditions. Option B uses 'and' for both conditions and correctly checks for the absence of 'aws:kms' encryption.
Why the other options are wrong
- A. Incorrectly uses 'not equal' for the encryption type, but the 'not' operator before 'json.serverSideEncryption.type' is syntactically incorrect for checking a specific value; '!=' is the correct operator.
- B. Uses 'or' instead of 'and' between the public access and encryption conditions, which would return buckets that are either publicly accessible OR not encrypted, not necessarily both.
- C. Checks for 'None' as the encryption type, which is not how the absence of SSE-KMS is typically represented in RQL for this specific field; '!= 'aws:kms'' is the appropriate check.
RQL Logical Operator: AND
The 'AND' logical operator in Resource Query Language (RQL) is used to combine two or more conditions, returning results only when all specified conditions are true.
- Used to narrow down results by requiring multiple criteria to be met.
- Essential for precise resource filtering and policy creation.
- Combines conditions, ensuring all are satisfied.
Memory trick: Combine conditions, AND get precise results.