Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

A security engineer is tasked with deploying Prisma Cloud Defenders to a Kubernetes cluster. The organization requires that the Defenders automatically scale with the cluster's nodes, ensuring continuous coverage even as the cluster expands or contracts. Which Kubernetes deployment mechanism is the most appropriate for achieving this automatic scaling and node-level deployment for Defenders?

  1. ADeployment
  2. BDaemonSet
  3. CJob
  4. DStatefulSet
Show answer & explanation

Correct answer: B. DaemonSet

A DaemonSet ensures that a copy of a Pod (in this case, the Prisma Cloud Defender) runs on every node in the cluster. This guarantees automatic deployment to new nodes and continuous coverage as the cluster scales.

Why the other options are wrong

  • A. A Deployment manages a replicated set of Pods, but doesn't guarantee one per node.
  • C. A Job runs a Pod to completion, suitable for batch tasks, not continuous node-level agents.
  • D. A StatefulSet is for stateful applications and provides stable network identities/persistent storage, not node-level deployment.

Kubernetes DaemonSet

A Kubernetes workload resource that ensures a copy of a Pod runs on all (or some) nodes in a cluster.

  • Ideal for node-level agents, monitoring, or logging services.
  • Automatically deploys to new nodes added to the cluster.
  • Ensures continuous presence on every relevant node.

Memory trick: Decide the 'set' for your Pod: Deployment for scale, Stateful for state, Daemon for every node, Job for one-off tasks.

More Cloud Workload Protection Platform (CWPP) questions