Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard
A security orchestration engineer is reviewing a playbook that processes incident data. They notice that a particular script task, which performs a complex calculation, takes a significant amount of time to execute. This script's output is only used much later in the playbook, and its execution does not block any other initial tasks. To optimize the playbook's overall execution time without changing the script's logic, what is the best approach to configure this script task?
- ABreak down the script into smaller, sequential tasks.
- BSet the 'Timeout' property for the script task to a higher value.
- CConvert the script task into a 'Manual' task to allow human intervention.
- DConfigure the script task to run 'Asynchronously' if its output is not immediately needed.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the script task to run 'Asynchronously' if its output is not immediately needed.
Configuring a task to run 'Asynchronously' allows the playbook to immediately proceed to subsequent tasks without waiting for the asynchronous task to complete. This is ideal for long-running tasks whose outputs are not immediately required, optimizing overall playbook execution time.
Why the other options are wrong
- A. Breaking down the script might improve its internal efficiency, but it doesn't address the playbook's overall execution flow in the context of other tasks if its output is not blocking.
- B. Setting a higher 'Timeout' only prevents the task from failing prematurely; it does not accelerate its execution or allow the playbook to proceed concurrently.
- C. Converting to a 'Manual' task would delay the playbook significantly, requiring human action, which is contrary to optimization goals.
Asynchronous Task Execution
In Cortex XSOAR, configuring a task to run asynchronously allows the playbook to start the task and immediately proceed to subsequent tasks without waiting for the asynchronous task to complete, optimizing overall execution time for non-blocking operations.
- Playbook does not wait for task completion.
- Useful for long-running, non-blocking tasks.
- Improves overall playbook execution speed.
- Requires careful management of dependencies for later tasks.
Memory trick: Don't wait for the slow one if you don't need its results right away.