Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformHard
A security engineer is analyzing the network architecture for a new Prisma Cloud Enterprise deployment. They need to ensure that the Prisma Cloud console can successfully communicate with the deployed Defenders in the customer's cloud environments to receive security events and posture data. Which network communication direction and port are critical for this interaction?
- AConsole to Defenders, TCP 443
- BConsole to Defenders, TCP 8080
- CDefenders to Console, TCP 443
- DDefenders to Console, UDP 514
Show answer & explanationAnswer & explanation
Correct answer: C. Defenders to Console, TCP 443
Prisma Cloud Defenders initiate outbound communication to the Prisma Cloud console over TCP port 443 (HTTPS). This design allows Defenders to operate in customer networks without requiring inbound firewall rules, enhancing security.
Why the other options are wrong
- A. The Console does not initiate communication to Defenders; Defenders are designed to be outbound-only for connection.
- B. TCP 8080 is not the standard port for Defender-Console communication; 443 is used for secure HTTPS.
- D. UDP 514 is for syslog, not the primary control plane communication between Defenders and the Console.
Prisma Cloud Defender Outbound Communication
Prisma Cloud Defenders establish an outbound, encrypted connection to the Prisma Cloud console over TCP port 443 to send security telemetry and receive configuration updates.
- Communication is always initiated by the Defender (outbound).
- Uses standard HTTPS (TCP 443) for secure transport.
- Simplifies firewall rules in customer environments by avoiding inbound connections.
Memory trick: Defenders 'call out' to the Console securely on 443.