Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Workload Protection Platform (CWPP)Medium

A security engineer is configuring Prisma Cloud to protect a multi-account AWS environment. They need to ensure that all EC2 instances across various accounts are automatically scanned for vulnerabilities and compliance deviations without manual intervention per instance. Which Prisma Cloud Defender deployment method is most suitable for this requirement?

  1. ADeploying Defenders as a Kubernetes DaemonSet within each EC2 instance.
  2. BDeploying individual Defenders manually on each EC2 instance.
  3. CUtilizing the Host Auto-Defend feature with an AWS CloudFormation template.
  4. DImplementing a serverless Defender for each EC2 instance.
Show answer & explanation

Correct answer: C. Utilizing the Host Auto-Defend feature with an AWS CloudFormation template.

The Host Auto-Defend feature, particularly when integrated with cloud-native templates like AWS CloudFormation, allows for automated deployment of Defenders across a large number of instances in a multi-account environment, ensuring comprehensive coverage without manual effort.

Why the other options are wrong

  • A. Kubernetes DaemonSets are for container orchestration platforms, not directly for individual EC2 instances.
  • B. Manual deployment is not scalable or efficient for a multi-account environment with many instances.
  • D. Serverless Defenders are designed for serverless functions (e.g., AWS Lambda), not EC2 instances.

Host Auto-Defend

Prisma Cloud's Host Auto-Defend feature automates the deployment of Defenders to hosts (e.g., EC2 instances) in cloud environments, ensuring consistent security coverage.

  • Automates Defender deployment on cloud hosts.
  • Integrates with cloud-native deployment tools like CloudFormation.
  • Ensures widespread security coverage without manual intervention.

Memory trick: Auto-Defend is the cloud's best friend for host protection.

More Cloud Workload Protection Platform (CWPP) questions