Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy

A security engineer is developing a playbook that initiates a containment action on an endpoint, such as isolating it from the network. This action is critical and irreversible. Before performing this action, the playbook must prompt a human analyst for explicit approval. If approval is granted, the action proceeds; otherwise, the playbook logs the denial and ends. Which playbook task type is specifically designed for this human interaction and decision-making?

  1. AA 'Script' task that calls a custom Python script for user input.
  2. BA 'Manual' task with approval options.
  3. CA 'Wait' task that pauses for a specific duration.
  4. DA 'Condition' task that checks a variable for 'Approved'.
Show answer & explanation

Correct answer: B. A 'Manual' task with approval options.

A 'Manual' task in Cortex XSOAR is specifically designed to pause playbook execution and prompt a human user for input, approval, or to perform a manual step, making it ideal for critical decision points.

Why the other options are wrong

  • A. While a script could prompt, a 'Manual' task is the native and more user-friendly way to get explicit human approval within the playbook flow.
  • C. A 'Wait' task pauses execution for time, not for human decision-making.
  • D. A 'Condition' task checks existing data; it doesn't prompt for new human input.

Manual Task

A playbook task in Cortex XSOAR that pauses automation and requires human interaction (e.g., approval, data entry, manual action completion) before the playbook can proceed.

  • Essential for human-in-the-loop workflows.
  • Can include questions, options, and assignees.
  • Playbook waits until the manual task is completed.

Memory trick: For critical decisions, always ask the human with a Manual Task.

More Playbooks questions