Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security orchestration engineer is reviewing a playbook that processes incident data. The playbook includes a 'Set' task that updates a custom incident field named 'incident.enrichment_status' to 'Completed'. Later in the playbook, a 'Condition' task checks the value of this field to determine if a subsequent set of tasks should run. During testing, the 'Condition' task sometimes evaluates incorrectly, even though the 'Set' task appears to have executed. What is the most likely reason for the inconsistent evaluation?

  1. AThe playbook is running in debug mode, causing inconsistent context updates.
  2. BThe 'Condition' task is using the wrong context path for the field.
  3. CAnother task is overwriting the 'incident.enrichment_status' field.
  4. DThe 'Set' task is configured to 'Do Not Propagate to Parent'.
Show answer & explanation

Correct answer: D. The 'Set' task is configured to 'Do Not Propagate to Parent'.

If a 'Set' task is configured with 'Do Not Propagate to Parent', its updates to the incident fields will not be immediately reflected in the main incident object or visible to subsequent tasks that rely on the incident's state, leading to inconsistent evaluations.

Why the other options are wrong

  • A. Debug mode typically provides more insight; it doesn't inherently cause inconsistent context updates in this manner.
  • B. If the condition task was consistently using the wrong path, it would always fail, not just sometimes.
  • C. While possible, 'Do Not Propagate to Parent' is a more direct and common cause for *inconsistent* updates from a specific 'Set' task.

Context Propagation

The mechanism by which data written to the playbook context (e.g., by 'Set' tasks) is made available to parent playbooks or incident fields, controlled by propagation settings.

  • Crucial for data visibility across playbook scopes.
  • 'Do Not Propagate to Parent' prevents updates from reaching the incident.
  • Impacts how incident fields are updated by playbook tasks.

Memory trick: If the context doesn't 'propagate', it's a ghost to other tasks.

More Playbooks questions