Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium
A security operations team is using Cortex XSOAR to manage incident response. They have a standard playbook for phishing incidents, but specific departments (e.g., Finance, HR) require additional, unique steps to be executed. To maintain a single, consistent main phishing playbook while allowing for departmental variations, which playbook design best practice should be employed?
- AAdd conditional tasks within the main playbook to check the department and execute specific steps.
- BCreate separate, entirely distinct playbooks for each department's phishing incidents.
- CUtilize sub-playbooks for each department's specific steps, called conditionally from the main playbook.
- DEmbed all departmental logic directly into a large Python script within the main playbook.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilize sub-playbooks for each department's specific steps, called conditionally from the main playbook.
Employing sub-playbooks for departmental-specific steps, called conditionally from a main playbook, allows for modularity, reusability of the main playbook, and easier management of unique departmental logic without creating overly complex or redundant playbooks.
Why the other options are wrong
- A. Adding many conditional tasks directly into the main playbook can make it very complex and difficult to read or maintain as more departments are added.
- B. Creating entirely distinct playbooks leads to duplication of common steps and makes updates to the core phishing process difficult to propagate.
- D. Embedding all logic in a large Python script reduces visibility, makes debugging harder, and is generally not a best practice for playbook design when native XSOAR features are available.
Playbook Modularity (Sub-Playbooks)
Sub-playbooks allow for breaking down complex workflows into smaller, reusable, and manageable components, promoting modularity and reducing complexity in main playbooks.
- Encapsulates specific logic or tasks.
- Promotes reusability across multiple playbooks.
- Improves readability and maintainability of complex workflows.
- Can be called conditionally based on incident context.
Memory trick: Build with interchangeable blocks, not one giant structure.