Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium
An incident response playbook includes a task to query a threat intelligence platform for indicators. Due to rate limiting on the external API, this task often fails when multiple incidents trigger the playbook concurrently. The security engineer needs to implement a mechanism to automatically retry the query with an increasing delay if it fails, without causing the entire playbook to fail immediately. Which playbook task setting should be configured?
- AConfigure the 'Retries' and 'Retry Interval' settings for the task.
- BEnable 'Continue on error' and add a Conditional task.
- CEmbed the query in a Python script with custom retry logic.
- DSet the 'Critical' checkbox for the task.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure the 'Retries' and 'Retry Interval' settings for the task.
The 'Retries' and 'Retry Interval' settings are specifically designed to handle transient failures by automatically re-attempting a task after a specified delay, which is ideal for overcoming rate-limiting issues without complex custom scripting.
Why the other options are wrong
- B. While 'Continue on error' prevents immediate failure, it doesn't implement automatic retries; a Conditional task would only check for failure, not re-attempt.
- C. While a custom script could implement this, XSOAR's built-in retry mechanism is simpler and more efficient for this common use case.
- D. Setting 'Critical' would cause the playbook to fail immediately, which is the opposite of the desired behavior.
Task Retries
Task 'Retries' settings allow a playbook task to be automatically re-executed a specified number of times with a defined interval if its initial execution fails, typically used for transient errors.
- Handles transient failures (e.g., rate limits, network glitches).
- Automatically re-attempts task execution.
- Configurable number of retries and delay.
Memory trick: If at first you don't succeed, retry is what you need.