Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy
A security analyst is designing a playbook to automate the initial triage of security incidents. They want to ensure that a specific set of enrichment tasks always executes, regardless of whether previous tasks in the playbook succeed or fail. Which task property should be configured to achieve this behavior?
- AAlways Execute
- BContinue On Error
- CRequired Input
- DIs Critical
Show answer & explanationAnswer & explanation
Correct answer: A. Always Execute
The 'Always Execute' property ensures that a task runs irrespective of the success or failure of preceding tasks, making it suitable for essential enrichment steps that should always occur during incident triage.
Why the other options are wrong
- B. 'Continue On Error' allows the playbook to proceed if the specific task fails, but doesn't guarantee its execution if a prior task fails.
- C. 'Required Input' ensures necessary data is present before the task runs, but doesn't control its execution based on prior task status.
- D. 'Is Critical' affects playbook execution flow if the task fails, but doesn't guarantee execution if a prior task fails.
Always Execute Task Property
A task property in Cortex XSOAR playbooks that, when enabled, ensures the task will run even if a preceding task in the playbook fails.
- Guarantees task execution regardless of upstream task status.
- Useful for essential cleanup, logging, or enrichment tasks.
- Overrides normal playbook flow logic for task execution.
Memory trick: Always be executing the important tasks, come what may.