Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy

A security analyst is developing a playbook in Cortex XSOAR to automate the enrichment of IP addresses. The playbook needs to execute a script that takes the IP address as an input and returns a reputation score. What is the most efficient way to pass the IP address from a playbook task to the script?

  1. AUse a context output from a previous task as the script's argument.
  2. BHardcode the IP address directly into the script's code.
  3. CStore the IP address in a global variable accessible by all playbooks.
  4. DPrompt the user to manually enter the IP address during playbook execution.
Show answer & explanation

Correct answer: A. Use a context output from a previous task as the script's argument.

Using context outputs is the standard and most efficient way to pass data between tasks and scripts within a Cortex XSOAR playbook, ensuring dynamic and automated execution.

Why the other options are wrong

  • B. Hardcoding makes the script inflexible and non-reusable for different IP addresses.
  • C. Global variables are generally used for persistent data across multiple playbooks or long-term settings, not for transient data flow between tasks in a single execution.
  • D. Manual input defeats the purpose of automation and is not efficient for repetitive tasks.

Playbook Context

Playbook context is a dynamic data store that holds information generated or consumed by tasks within a playbook's execution. It enables data sharing and flow between different playbook components.

  • Data is stored as key-value pairs.
  • Accessible by all tasks and scripts in the current playbook instance.
  • Crucial for automation and orchestration.

Memory trick: Context Connects Components Clearly.

More Playbooks questions