Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy

A security analyst is debugging a complex playbook that involves several nested sub-playbooks. They observe that the playbook sometimes gets stuck, and the execution trace shows a task within a sub-playbook running indefinitely without completing. Which playbook task property, when configured, can prevent this specific issue by automatically failing the task after a set duration?

  1. APolling Interval
  2. BRetries
  3. CTimeout
  4. DCritical Task
Show answer & explanation

Correct answer: C. Timeout

The Timeout property for a task defines the maximum duration a task is allowed to run before Cortex XSOAR automatically terminates it and marks it as failed. This prevents tasks from running indefinitely and causing playbooks to get stuck.

Why the other options are wrong

  • A. Polling Interval specifies how often Cortex XSOAR checks for updates from an external system for asynchronous tasks, not a limit on total execution time.
  • B. Retries define how many times a failed task should be re-attempted, not a limit on its initial execution duration.
  • D. Critical Task marks a task as essential, meaning its failure can impact the overall incident status, but it doesn't prevent indefinite execution.

Task Timeout

A configuration setting for a playbook task that specifies the maximum amount of time the task is allowed to execute before it is automatically terminated and marked as failed.

  • Prevents indefinite task execution.
  • Ensures playbook progression.
  • Configured in task settings.

Memory trick: Don't let tasks 'hang' around too long, set a 'time-out'!

More Playbooks questions