Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard
A security orchestration engineer is reviewing a playbook and notices that a particular script task is executed multiple times with the same input, even though its output rarely changes. This is causing unnecessary load on an external API. To optimize this, the engineer wants to ensure the script is only run once for a given input and its result is reused if the same input is encountered again within the playbook's execution. Which playbook best practice addresses this optimization?
- AUsing a sub-playbook with an 'Auto-Extract' feature enabled.
- BRefactoring the script to store results in a global variable.
- CLeveraging playbook caching for script outputs.
- DImplementing a 'While Loop' to check if the script has run before.
Show answer & explanationAnswer & explanation
Correct answer: C. Leveraging playbook caching for script outputs.
Playbook caching allows you to store the results of a task (like a script's output) for a specified duration. If the same task is called with the same inputs within that duration, the cached result is returned instead of re-executing the task, significantly reducing redundant API calls and improving performance.
Why the other options are wrong
- A. Sub-playbooks are for modularity, and 'Auto-Extract' is for indicator extraction, neither directly provides call caching for script outputs.
- B. While a global variable could store results, XSOAR's native caching mechanism is more robust, automatically handles expiration, and is designed for task-level optimization without manual script refactoring for every cached output.
- D. A 'While Loop' is for conditional repetition, not caching or result reuse.
Playbook Task Caching
Playbook task caching in Cortex XSOAR allows the results of a task (e.g., script output, integration command result) to be stored. If the same task is invoked again with identical inputs within a defined cache duration, the cached result is returned instead of re-executing the task.
- Reduces redundant API calls and processing.
- Improves playbook performance and efficiency.
- Configurable per task with a cache duration.
Memory trick: Caching Cuts Call Cycles.