Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Hard
A security engineer needs to deploy Prisma Cloud Defenders across a large fleet of virtual machines (VMs) in an automated and scalable manner. These VMs are provisioned dynamically, and manual agent installation is not feasible. Which deployment method for Host Defenders would best support this requirement for automation and scalability in a cloud environment?
- AManual installation via SSH
- BKubernetes DaemonSet
- CGolden Image integration
- DServerless function invocation
Show answer & explanationAnswer & explanation
Correct answer: C. Golden Image integration
Integrating the Host Defender into a Golden Image (AMI, VM template) allows for automated and scalable deployment, as every new VM provisioned from that image will automatically include the Defender agent, eliminating the need for manual installation.
Why the other options are wrong
- A. Manual installation is not scalable or automated for dynamic environments.
- B. Kubernetes DaemonSet is for deploying agents in Kubernetes clusters, not directly on standalone VMs.
- D. Serverless function invocation is for securing serverless applications, not deploying agents on VMs.
Prisma Cloud Host Defender Golden Image Deployment
Deploying Prisma Cloud Host Defenders via Golden Images (e.g., AMIs in AWS, custom images in Azure/GCP) involves pre-installing the Defender agent into a base VM image. This enables automated and scalable deployment, as all new VMs provisioned from that image will include the Defender.
- Automated and scalable deployment
- Defender is pre-installed in the base image
- Suitable for dynamically provisioned VMs
- Reduces operational overhead
Memory trick: Golden Images are the blueprint for automated Defender deployment.