Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium
A security orchestration engineer is developing a complex playbook that involves multiple sub-playbooks. They want to pass a specific piece of information, say a `file_hash`, from the main playbook to a sub-playbook, and then receive an enriched `file_reputation` back from that sub-playbook to continue processing in the main playbook. How should this data exchange be correctly configured?
- ADefine `file_hash` as a sub-playbook input and `file_reputation` as a sub-playbook output.
- BPass `file_hash` as a direct argument to the sub-playbook task and retrieve `file_reputation` from the sub-playbook's task outputs.
- CStore `file_hash` in the global context and assume the sub-playbook can read/write it.
- DUse a dedicated script to transfer data between the main playbook and the sub-playbook context.
Show answer & explanationAnswer & explanation
Correct answer: A. Define `file_hash` as a sub-playbook input and `file_reputation` as a sub-playbook output.
The standard and best practice for explicit data exchange between a main playbook and a sub-playbook is to define inputs for data coming into the sub-playbook and outputs for data returning from it. This creates a clear interface and promotes modularity.
Why the other options are wrong
- B. Direct arguments are typically for single values to a command, and while sub-playbook tasks have outputs, defining a formal sub-playbook output for `file_reputation` is cleaner and more explicit for data return.
- C. While global context can be accessed, explicit inputs/outputs are a best practice for sub-playbooks to ensure clear data contracts and prevent unintended side effects.
- D. Using a dedicated script for data transfer is unnecessary when the platform provides native input/output mechanisms for sub-playbooks.
Sub-Playbook Inputs and Outputs
Sub-playbooks can be configured with specific inputs to receive data from the calling playbook and outputs to return processed data, creating a clear and modular interface for data exchange.
- Inputs define data received by the sub-playbook.
- Outputs define data returned by the sub-playbook to the caller.
- Enforces clear data contracts between playbooks.
- Enhances modularity, reusability, and readability.
Memory trick: Give it only what it needs (inputs), and it will give you back what you asked for (outputs).