Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security analyst is designing a playbook to automate the process of collecting evidence from compromised endpoints. This process involves executing a series of commands on multiple endpoints identified in an incident. Due to network latency and the nature of forensic tools, some commands can take a long time to complete. The analyst wants to ensure that the playbook waits for ALL commands on ALL endpoints to finish before proceeding to the next stage of analysis. Which playbook task configuration achieves this synchronization?

  1. AUse parallel branches for each endpoint's commands, followed by a 'Join' task.
  2. BSet each command task to 'Stop on Error'.
  3. CPlace all command tasks in a 'For Each' loop and follow it with a 'Wait' task.
  4. DImplement a custom script that periodically checks the status of all running commands.
Show answer & explanation

Correct answer: A. Use parallel branches for each endpoint's commands, followed by a 'Join' task.

To wait for multiple concurrent paths (e.g., commands on different endpoints) to complete before proceeding, the 'Join' task is specifically designed for this purpose in Cortex XSOAR, synchronizing parallel branches.

Why the other options are wrong

  • B. 'Stop on Error' only controls error handling, not synchronization of completion.
  • C. A 'For Each' loop processes items sequentially (unless nested parallel tasks are used), and a 'Wait' task typically waits for a specific duration or condition, not for all tasks in a loop to finish in parallel.
  • D. A custom script could achieve this, but the 'Join' task is the native and more efficient playbook construct for this exact synchronization requirement.

Playbook Join Task

A playbook task that synchronizes the execution of multiple parallel branches, ensuring that all preceding tasks within those branches have completed before the playbook proceeds to subsequent tasks.

  • Essential for managing concurrent workflows.
  • Ensures all required prerequisites are met before continuing.
  • Prevents race conditions in parallel execution.

Memory trick: When many paths run together, they must 'Join' before moving on.

More Playbooks questions