Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy
A security orchestration engineer is developing a playbook to automate the initial triage of security alerts. The playbook needs to ingest various alert fields (e.g., `source_ip`, `destination_ip`, `alert_name`) as inputs. These inputs are then used by subsequent tasks and scripts throughout the playbook. To ensure these inputs are clearly defined, validated, and easily accessible within the playbook's context, what is the best practice for configuring them?
- ADefine them as 'Playbook Inputs' and map incoming incident fields to these inputs.
- BStore all incoming fields in a separate 'Data Store' integration.
- CManually extract each field using a Python script at the start of the playbook.
- DAccess them directly from the incident object using DQL within each task.
Show answer & explanationAnswer & explanation
Correct answer: A. Define them as 'Playbook Inputs' and map incoming incident fields to these inputs.
Defining 'Playbook Inputs' allows for clear, type-defined parameters for the playbook, which can then be mapped from incoming incident fields. This makes them easily accessible within the playbook's context, promotes validation, and improves readability.
Why the other options are wrong
- B. A 'Data Store' integration is for persistent storage of data, not for defining and accessing immediate playbook parameters.
- C. Manually extracting fields with a script is less efficient and less readable than using native playbook input definitions.
- D. While direct DQL access is possible, defining playbook inputs provides better structure, validation, and documentation for the playbook's expected parameters, especially when dealing with multiple fields.
Playbook Inputs
Playbook Inputs are defined parameters that allow a playbook to receive data from an external source (e.g., an incident, another playbook), making that data accessible within the playbook's context for use by tasks and scripts.
- Define the data required for the playbook to run.
- Can be mapped from incident fields or other context data.
- Accessible within the playbook using `inputs.<input_name>`.
- Promote clear interfaces and data validation.
Memory trick: Give the playbook its ingredients through its inputs.