Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A security engineer is tasked with configuring Prisma Cloud to identify all AWS S3 buckets that are publicly accessible AND are not encrypted with Server-Side Encryption with AWS Key Management Service (SSE-KMS). Which RQL query correctly identifies these resources?

  1. Aconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and not json.serverSideEncryption.type = 'aws:kms'
  2. Bconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true or json.serverSideEncryption.type != 'aws:kms'
  3. Cconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and json.serverSideEncryption.type = 'None'
  4. Dconfig from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and json.serverSideEncryption.type != 'aws:kms'
Show answer & explanation

Correct answer: D. config from cloud.resource where resourceType = 'aws_s3_bucket' and json.publicAccess = true and json.serverSideEncryption.type != 'aws:kms'

The query needs to identify S3 buckets that meet two conditions simultaneously: public accessibility AND lack of SSE-KMS encryption. The 'AND' logical operator correctly links these conditions. Option B uses 'and' for both conditions and correctly checks for the absence of 'aws:kms' encryption.

Why the other options are wrong

  • A. Incorrectly uses 'not equal' for the encryption type, but the 'not' operator before 'json.serverSideEncryption.type' is syntactically incorrect for checking a specific value; '!=' is the correct operator.
  • B. Uses 'or' instead of 'and' between the public access and encryption conditions, which would return buckets that are either publicly accessible OR not encrypted, not necessarily both.
  • C. Checks for 'None' as the encryption type, which is not how the absence of SSE-KMS is typically represented in RQL for this specific field; '!= 'aws:kms'' is the appropriate check.

RQL Logical Operator: AND

The 'AND' logical operator in Resource Query Language (RQL) is used to combine two or more conditions, returning results only when all specified conditions are true.

  • Used to narrow down results by requiring multiple criteria to be met.
  • Essential for precise resource filtering and policy creation.
  • Combines conditions, ensuring all are satisfied.

Memory trick: Combine conditions, AND get precise results.

More Cloud Security Posture Management (CSPM) questions