Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security operations team is building a playbook to automate the initial triage of phishing incidents. They need to ensure that regardless of whether an enrichment task succeeds or fails (e.g., querying a threat intelligence platform), a subsequent task to notify the security analyst is always executed. Which task property should be configured on the notification task to guarantee its execution?

  1. APlace it in a 'Join' task.
  2. BConfigure a 'Timeout' of 0 seconds.
  3. CEnable the 'Always Execute' property.
  4. DSet a 'Retries' value of 0.
Show answer & explanation

Correct answer: C. Enable the 'Always Execute' property.

The 'Always Execute' property ensures that a task will run regardless of the success or failure of preceding tasks in the playbook. This is crucial for tasks like notifications or cleanup that must happen irrespective of intermediate task outcomes.

Why the other options are wrong

  • A. A 'Join' task waits for multiple parallel branches to complete before proceeding, but it doesn't guarantee execution of its subsequent tasks if a task in one of the joined branches fails.
  • B. A 'Timeout' of 0 seconds means the task will attempt to run indefinitely without timing out, which is generally not recommended and does not guarantee execution if a prior task fails.
  • D. Setting 'Retries' to 0 would prevent any re-attempts if the task itself fails, but it doesn't guarantee execution if a *preceding* task fails.

Always Execute Task Property

A configuration setting for a playbook task that ensures the task will run even if previous tasks in its execution path have failed.

  • Guarantees task execution.
  • Useful for cleanup or notification tasks.
  • Overrides upstream task failures.

Memory trick: No matter what, this task 'always goes'!

More Playbooks questions