Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy
A security analyst is developing a playbook in Cortex XSOAR to automate the enrichment of IP addresses. The playbook needs to execute a script that takes the IP address as an input and returns a reputation score. What is the most efficient way to pass the IP address from a playbook task to the script?
- AUse a context output from a previous task as the script's argument.
- BHardcode the IP address directly into the script's code.
- CStore the IP address in a global variable accessible by all playbooks.
- DPrompt the user to manually enter the IP address during playbook execution.
Show answer & explanationAnswer & explanation
Correct answer: A. Use a context output from a previous task as the script's argument.
Using context outputs is the standard and most efficient way to pass data between tasks and scripts within a Cortex XSOAR playbook, ensuring dynamic and automated execution.
Why the other options are wrong
- B. Hardcoding makes the script inflexible and non-reusable for different IP addresses.
- C. Global variables are generally used for persistent data across multiple playbooks or long-term settings, not for transient data flow between tasks in a single execution.
- D. Manual input defeats the purpose of automation and is not efficient for repetitive tasks.
Playbook Context
Playbook context is a dynamic data store that holds information generated or consumed by tasks within a playbook's execution. It enables data sharing and flow between different playbook components.
- Data is stored as key-value pairs.
- Accessible by all tasks and scripts in the current playbook instance.
- Crucial for automation and orchestration.
Memory trick: Context Connects Components Clearly.