Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy
A security engineer is developing a playbook that initiates a containment action on an endpoint, such as isolating it from the network. This action is critical and irreversible. Before performing this action, the playbook must prompt a human analyst for explicit approval. If approval is granted, the action proceeds; otherwise, the playbook logs the denial and ends. Which playbook task type is specifically designed for this human interaction and decision-making?
- AA 'Script' task that calls a custom Python script for user input.
- BA 'Manual' task with approval options.
- CA 'Wait' task that pauses for a specific duration.
- DA 'Condition' task that checks a variable for 'Approved'.
Show answer & explanationAnswer & explanation
Correct answer: B. A 'Manual' task with approval options.
A 'Manual' task in Cortex XSOAR is specifically designed to pause playbook execution and prompt a human user for input, approval, or to perform a manual step, making it ideal for critical decision points.
Why the other options are wrong
- A. While a script could prompt, a 'Manual' task is the native and more user-friendly way to get explicit human approval within the playbook flow.
- C. A 'Wait' task pauses execution for time, not for human decision-making.
- D. A 'Condition' task checks existing data; it doesn't prompt for new human input.
Manual Task
A playbook task in Cortex XSOAR that pauses automation and requires human interaction (e.g., approval, data entry, manual action completion) before the playbook can proceed.
- Essential for human-in-the-loop workflows.
- Can include questions, options, and assignees.
- Playbook waits until the manual task is completed.
Memory trick: For critical decisions, always ask the human with a Manual Task.