Question 1
A financial services company has deployed Prisma Cloud to monitor its AWS environment. A security architect needs to create a custom policy to detect any S3 bucket that is publicly accessible but does NOT have a 'data-classification' tag with the value 'public'. Which RQL query correctly identifies these non-compliant S3 buckets?
Answer and explanation
Correct answer: C
This RQL query correctly identifies the target resources. It uses the aws-s3-bucket-list API to get bucket configurations, checks if publicAccess is true, and then uses a logical OR to find buckets where the 'data-classification' tag is either not equal to 'public' or is not defined at all. This combination accurately captures the security requirement.