Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

An organization is deploying Prisma Cloud Defenders to protect their on-premises virtual machines. Which deployment method for the Host Defender ensures the lowest operational overhead for managing the Defender lifecycle across a large fleet of Linux VMs?

  1. AEmbedding the Defender into the VM's base image.
  2. BDeployment via a configuration management tool (e.g., Ansible, Chef).
  3. CUsing a custom script to download and install on boot.
  4. DManual installation via SSH on each VM.
Show answer & explanation

Correct answer: B. Deployment via a configuration management tool (e.g., Ansible, Chef).

Using a configuration management tool like Ansible or Chef allows for automated, scalable, and consistent deployment and management of the Host Defender across a large fleet of VMs, significantly reducing operational overhead compared to manual methods or custom scripts.

Why the other options are wrong

  • A. Embedding in a base image helps with initial deployment but complicates updates and lifecycle management.
  • C. Custom scripts can be brittle and lack the robust management features of dedicated configuration management tools.
  • D. Manual installation is time-consuming and error-prone for large fleets.

Automated Defender Deployment

Utilizing configuration management tools or orchestration platforms to deploy and manage Prisma Cloud Defenders efficiently across large infrastructures.

  • Reduces manual effort and errors.
  • Ensures consistent configurations.
  • Facilitates scalable updates and maintenance.

Memory trick: For many hosts, automation is the only way to go.

More Cloud Workload Protection Platform (CWPP) questions