Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard

A security engineer is developing a playbook that interacts with a third-party API. The API requires a token that expires every hour. To avoid hardcoding the token or manually updating it, the playbook needs to automatically refresh the token when it's about to expire and use the new token for subsequent API calls. Which combination of playbook components and best practices should be used?

  1. AStore the token as a playbook input and manually update it hourly.
  2. BA sub-playbook for token management, called conditionally before API tasks, with the token stored in context.
  3. CA 'For Each' loop to iterate through potential tokens, and a manual task for refreshing.
  4. DA 'While Loop' to continuously check token expiration and a custom script to refresh it.
Show answer & explanation

Correct answer: B. A sub-playbook for token management, called conditionally before API tasks, with the token stored in context.

Encapsulating token management in a sub-playbook ensures reusability and modularity. Calling it conditionally (e.g., if the current token is expired or near expiration) before API tasks, and storing the refreshed token in context, provides an automated, dynamic, and clean solution.

Why the other options are wrong

  • A. Manually updating inputs hourly is not automation and is error-prone.
  • C. A 'For Each' loop is for iterating over lists, not continuous token management. Manual tasks defeat automation.
  • D. A 'While Loop' checking continuously is inefficient. A conditional check before use is better. A sub-playbook is more modular than a standalone script.

Dynamic Token Management

Dynamic token management in playbooks involves automatically refreshing API tokens when they expire or are about to expire, and ensuring the updated token is used for subsequent authenticated requests, typically using conditional logic and context data.

  • Prevents playbook failures due to expired tokens.
  • Increases automation and reduces manual intervention.
  • Often uses sub-playbooks for modularity and reusability.

Memory trick: Sub-Playbooks Secure System Secrets Smoothly.

More Playbooks questions