Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
A security engineer is configuring a Prisma Cloud Defender for a critical Kubernetes cluster. They need to ensure that the Defender can inspect all network traffic entering and exiting pods, collect process activity, and enforce runtime policies without requiring manual configuration changes on individual worker nodes. Which deployment method does Prisma Cloud recommend for comprehensive container and host visibility in Kubernetes?
- ADeploying Defenders as a DaemonSet across all worker nodes.
- BDeploying Defenders as individual Pods on specific nodes.
- CDeploying Defenders as a Deployment with a fixed number of replicas.
- DDeploying Defenders manually via SSH to each worker node.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploying Defenders as a DaemonSet across all worker nodes.
Deploying Defenders as a DaemonSet ensures a Defender Pod runs on every worker node in the Kubernetes cluster. This provides comprehensive visibility and enforcement capabilities across all hosts and containers, automatically scaling and maintaining coverage as nodes are added or removed.
Why the other options are wrong
- B. This approach lacks comprehensive coverage and automatic scaling.
- C. A Deployment manages a fixed number of pods, not necessarily one per node, which would lead to incomplete coverage.
- D. Manual deployment is inefficient, prone to errors, and does not scale automatically in a dynamic Kubernetes environment.
Defender DaemonSet Deployment
Prisma Cloud's recommended method for deploying Defenders in Kubernetes, ensuring a Defender runs on every worker node.
- Provides comprehensive host and container visibility.
- Automatically scales with the Kubernetes cluster.
- Simplifies management and ensures consistent policy enforcement.
Memory trick: DaemonSet: Every node gets a Defender, like a personal bodyguard.