[gruebel (accepted answer)]: depending on what you want to achieve you can use .*. to reference all the managed_rule_set blocks, like that ``` - cond_type: "attribute" resource_types: - "azurerm_web_application_firewall_policy" attribute: "managed_rules.managed_rule_set.*.type" operator: "contains" value: "OWASP" ```

Context: Stack Overflow #70879881 (accepted answer, 3 votes, 1 answers): I am currently learning policy-as-code with the help of Checkov. In the process, I am also writing my own policies. I would like to write a policy that checks the content inside "managed_rule_set". I know how to reference the attributes from the terraform-file correctly, but not how to do it in this particular case. I define the custom policies via a yaml-file and orient myself on the documentation of checkov. Terraform-file: tf-file ``` resource "azurerm_web_application_firewall_policy" "waf_network" { name = "waf-${var.tag_project}-network-${var.tag_environment}" resource_group_name = azurer