Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium
A security analyst is building a playbook to automate the initial triage of phishing incidents. The playbook should only execute if the incident type is 'Phishing' AND the incident status is 'New'. If these conditions are not met, the playbook should not start. Which setting should be configured at the playbook level to enforce these conditions?
- AAn initial Conditional task at the beginning of the playbook.
- BThe 'Playbook Entry Conditions' in the playbook settings.
- CA manual task requiring analyst approval for non-phishing incidents.
- DA script that checks incident type and status and then exits if not met.
Show answer & explanationAnswer & explanation
Correct answer: B. The 'Playbook Entry Conditions' in the playbook settings.
Playbook Entry Conditions are specifically designed to define criteria that must be met for a playbook to start execution. If these conditions are not satisfied, the playbook will not run, saving resources and ensuring proper incident handling.
Why the other options are wrong
- A. An initial Conditional task allows the playbook to start and then branch, but the requirement is for the playbook to *not start* if conditions aren't met.
- C. A manual task would allow the playbook to start and then pause, which is not the desired 'not start' behavior.
- D. While a script could achieve this, Playbook Entry Conditions are a built-in, more declarative, and efficient method for this specific requirement.
Playbook Entry Conditions
Playbook Entry Conditions are a set of rules defined at the playbook level that determine whether a playbook is allowed to start execution for a given incident. If the conditions are not met, the playbook will not run.
- Prevents playbooks from starting unnecessarily.
- Evaluated before any tasks in the playbook.
- Conserves resources and ensures relevant execution.
Memory trick: Entry conditions: if they're not green, the playbook's not seen.