Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security operations team is using Cortex XSOAR to manage incident response. They have a standard playbook for phishing incidents, but specific departments (e.g., Finance, HR) require additional, unique steps to be executed. To maintain a single, consistent main phishing playbook while allowing for departmental variations, which playbook design best practice should be employed?

  1. AAdd conditional tasks within the main playbook to check the department and execute specific steps.
  2. BCreate separate, entirely distinct playbooks for each department's phishing incidents.
  3. CUtilize sub-playbooks for each department's specific steps, called conditionally from the main playbook.
  4. DEmbed all departmental logic directly into a large Python script within the main playbook.
Show answer & explanation

Correct answer: C. Utilize sub-playbooks for each department's specific steps, called conditionally from the main playbook.

Employing sub-playbooks for departmental-specific steps, called conditionally from a main playbook, allows for modularity, reusability of the main playbook, and easier management of unique departmental logic without creating overly complex or redundant playbooks.

Why the other options are wrong

  • A. Adding many conditional tasks directly into the main playbook can make it very complex and difficult to read or maintain as more departments are added.
  • B. Creating entirely distinct playbooks leads to duplication of common steps and makes updates to the core phishing process difficult to propagate.
  • D. Embedding all logic in a large Python script reduces visibility, makes debugging harder, and is generally not a best practice for playbook design when native XSOAR features are available.

Playbook Modularity (Sub-Playbooks)

Sub-playbooks allow for breaking down complex workflows into smaller, reusable, and manageable components, promoting modularity and reducing complexity in main playbooks.

  • Encapsulates specific logic or tasks.
  • Promotes reusability across multiple playbooks.
  • Improves readability and maintainability of complex workflows.
  • Can be called conditionally based on incident context.

Memory trick: Build with interchangeable blocks, not one giant structure.

More Playbooks questions