Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy
A security orchestration engineer is debugging a playbook and notices that a particular task, a command to query a large threat intelligence database, consistently runs for over 5 minutes and sometimes times out, causing the playbook to fail. This task is critical, but the engineer wants to allow it more time to complete before failing. Which task setting should be adjusted?
- AAdjust the 'Timeout' duration for the task.
- BEnable the 'Always Execute' property.
- CSet 'Continue On Error' to True.
- DIncrease the 'Retries' count for the task.
Show answer & explanationAnswer & explanation
Correct answer: A. Adjust the 'Timeout' duration for the task.
The 'Timeout' property for a task defines the maximum duration the task is allowed to run before it is automatically terminated and marked as failed. Increasing this value will give the long-running query more time to complete.
Why the other options are wrong
- B. 'Always Execute' ensures the task runs regardless of prior task failures, but does not affect its execution duration or timeout.
- C. 'Continue On Error' would allow the playbook to proceed if this task fails, but it doesn't prevent the task from timing out in the first place.
- D. Increasing 'Retries' would make the task attempt to run again after failure, but wouldn't prevent the initial timeout if the task consistently exceeds the current limit.
Playbook Task Timeout
The 'Timeout' property for a playbook task defines the maximum amount of time (in seconds) that the task is allowed to execute before it is automatically terminated and marked as a failure, preventing playbooks from hanging indefinitely.
- Prevents tasks from running indefinitely.
- Specified in seconds for each individual task.
- Can be adjusted to accommodate long-running operations.
- A value of 0 means no timeout (runs indefinitely).
Memory trick: Give the task enough time, but not forever.