Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard

A security analyst is debugging a playbook and observes that a specific script task, which is supposed to retrieve a list of compromised hosts, sometimes returns an empty list even when there should be data. Upon investigation, they find that the integration used by the script is occasionally timing out, but the script itself doesn't explicitly handle this timeout and just returns an empty list by default. The analyst confirms the integration is configured with a timeout of 30 seconds. To improve the playbook's reliability without modifying the script, they want the task to fail immediately if the integration command times out. Which playbook task setting should be adjusted?

  1. ASet the 'Timeout' for the task to 20 seconds.
  2. BIncrease the 'Retries' count for the task.
  3. CSet the 'Critical' checkbox for the task.
  4. DSet 'Continue on error' to 'No'.
Show answer & explanation

Correct answer: A. Set the 'Timeout' for the task to 20 seconds.

Setting a 'Timeout' at the task level that is lower than the integration's default timeout will cause the task itself to fail if the integration command takes too long, overriding the script's default behavior and preventing it from returning an empty list due to an implicit timeout.

Why the other options are wrong

  • B. Increasing retries would re-attempt the task, but doesn't guarantee a failure for a specific timeout within the script's execution.
  • C. Setting 'Critical' only determines what happens *after* the task fails; it doesn't control *when* the task fails due to a timeout.
  • D. Setting 'Continue on error' to 'No' ensures the playbook stops on any error, but doesn't explicitly fail on a timeout before the script returns a result.

Playbook Task Timeout

A Playbook Task Timeout defines the maximum duration a specific task is allowed to run. If the task exceeds this duration, it is automatically terminated and marked as failed, even if the underlying integration or script has a longer internal timeout.

  • Overrides integration/script internal timeouts.
  • Ensures tasks complete within expected timeframe.
  • Prevents playbooks from hanging indefinitely.

Memory trick: Time's up! If a task waits too long, the playbook sings its song.

More Playbooks questions