Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard

A security analyst is investigating a complex incident involving multiple malware samples. The playbook is designed to submit each unique malware sample (hash) to a sandbox for analysis. The sandbox integration can only process one sample at a time and has a rate limit of 5 submissions per minute. The playbook receives a list of 20 hashes. How should the analyst implement the submission process to respect the rate limit and ensure all samples are processed?

  1. AUse a 'For Each' loop to submit each hash, with a 12-second 'Wait' task after each submission.
  2. BUse a 'For Each' loop to submit each hash, and configure the sandbox integration's 'Rate Limit' setting to 5/minute.
  3. CSubmit all 20 hashes in parallel using multiple 'SandboxSubmission' tasks.
  4. DCreate 4 separate 'For Each' loops, each processing 5 hashes sequentially.
Show answer & explanation

Correct answer: B. Use a 'For Each' loop to submit each hash, and configure the sandbox integration's 'Rate Limit' setting to 5/minute.

Cortex XSOAR integrations often have built-in rate limit configurations. Utilizing the integration's native 'Rate Limit' setting is the most efficient and robust way to handle this, as the platform manages the timing and queuing automatically without requiring manual 'Wait' tasks or complex loop structures.

Why the other options are wrong

  • A. While a 12-second wait (60/5) would achieve the rate, manually adding 'Wait' tasks is less efficient and prone to errors compared to native integration features.
  • C. Submitting all in parallel would violate the rate limit and likely result in failures from the sandbox.
  • D. This is overly complex and still requires manual management of the rate limit, which is less robust than using the integration's native feature.

Integration Rate Limiting

A feature in Cortex XSOAR integrations that automatically controls the frequency of API calls to an external service, preventing exceeding the service's defined rate limits.

  • Configured directly on the integration instance.
  • Manages call timing automatically, no manual waits needed.
  • Crucial for respecting external API usage policies.

Memory trick: Don't rush the API; let the integration's rate limit handle the pace.

More Playbooks questions