Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium
An organization is deploying Prisma Cloud Defenders to protect their on-premises virtual machines. Which deployment method for the Host Defender ensures the lowest operational overhead for managing the Defender lifecycle across a large fleet of Linux VMs?
- AEmbedding the Defender into the VM's base image.
- BDeployment via a configuration management tool (e.g., Ansible, Chef).
- CUsing a custom script to download and install on boot.
- DManual installation via SSH on each VM.
Show answer & explanationAnswer & explanation
Correct answer: B. Deployment via a configuration management tool (e.g., Ansible, Chef).
Using a configuration management tool like Ansible or Chef allows for automated, scalable, and consistent deployment and management of the Host Defender across a large fleet of VMs, significantly reducing operational overhead compared to manual methods or custom scripts.
Why the other options are wrong
- A. Embedding in a base image helps with initial deployment but complicates updates and lifecycle management.
- C. Custom scripts can be brittle and lack the robust management features of dedicated configuration management tools.
- D. Manual installation is time-consuming and error-prone for large fleets.
Automated Defender Deployment
Utilizing configuration management tools or orchestration platforms to deploy and manage Prisma Cloud Defenders efficiently across large infrastructures.
- Reduces manual effort and errors.
- Ensures consistent configurations.
- Facilitates scalable updates and maintenance.
Memory trick: For many hosts, automation is the only way to go.