Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security analyst is debugging a complex playbook that involves multiple tasks. They notice that a particular script task is consistently failing, but the playbook continues to execute subsequent tasks, leading to incomplete incident resolution. The analyst needs to ensure that if this specific script task fails, the playbook immediately stops and marks the incident as 'Failed'. Which task-level setting should the analyst configure?

  1. ASet the 'Continue on error' option to 'Yes'.
  2. BSet the 'Critical' checkbox for the task.
  3. CDefine an 'Error Handler' sub-playbook for the task.
  4. DImplement a 'Conditional' task after the script to check its status.
Show answer & explanation

Correct answer: B. Set the 'Critical' checkbox for the task.

Marking a task as 'Critical' ensures that if it fails, the entire playbook execution stops immediately, and the incident is marked as 'Failed'. This is the direct solution for preventing continuation after a vital task's failure.

Why the other options are wrong

  • A. 'Continue on error' set to 'Yes' would allow the playbook to proceed, which is the opposite of the requirement.
  • C. An 'Error Handler' sub-playbook would allow for custom error recovery, but the requirement is to stop and fail the incident, which 'Critical' does directly.
  • D. A conditional task would add unnecessary complexity and wouldn't stop the playbook immediately; it would only decide on the next step after the failure has already occurred.

Critical Task Setting

The 'Critical' setting for a playbook task dictates that if this specific task fails during execution, the entire playbook immediately stops, and the associated incident is marked as 'Failed'.

  • Ensures essential tasks must succeed.
  • Stops playbook execution upon failure.
  • Marks incident as 'Failed' automatically.

Memory trick: Critical tasks, if they fall, bring the whole show to a halt.

More Playbooks questions