Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy
A security operations team is migrating their incident response playbooks to Cortex XSOAR. One of their existing procedures involves repeating a specific set of enrichment and analysis tasks for each suspicious IP address found in an incident. The number of IP addresses can vary significantly between incidents. Which playbook construct is best suited to efficiently automate this repetitive process for an unknown number of items?
- AA global script that processes all IP addresses in a single execution.
- BA conditional branch that checks if an IP exists and then calls a sub-playbook.
- CA 'For Each' loop that iterates over a list of IP addresses.
- DMultiple sequential tasks, each configured for a potential IP address.
Show answer & explanationAnswer & explanation
Correct answer: C. A 'For Each' loop that iterates over a list of IP addresses.
A 'For Each' loop is designed to iterate over a list of items, executing a set of tasks or a sub-playbook for each item, making it ideal for processing a variable number of IP addresses efficiently.
Why the other options are wrong
- A. A global script could process them, but a 'For Each' loop provides a more visual, maintainable, and native playbook way to manage the iteration and task execution.
- B. This approach would only handle one IP address per branch and would be cumbersome for multiple, unknown quantities.
- D. Creating multiple sequential tasks for potential IP addresses is impractical and not scalable for an unknown number.
For Each Loop
A playbook construct in Cortex XSOAR that iterates over a list of items (e.g., IP addresses, file hashes), executing a specified set of tasks or a sub-playbook for each item.
- Automates repetitive tasks for collections.
- Handles variable numbers of items dynamically.
- Can execute scripts, commands, or sub-playbooks per item.
Memory trick: For every item on the list, the loop repeats the steps.