Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard

A security analyst is developing a playbook that retrieves a list of indicators from a threat intelligence platform. The playbook then needs to filter this list to only include indicators that are of type 'IP' and have a 'severity' greater than 'medium'. After filtering, a sub-playbook should be called for each of these filtered indicators. Which playbook construct and context manipulation method should be used to achieve this filtering efficiently?

  1. AA 'For Each' loop with a custom 'Script' task to filter and then call the sub-playbook.
  2. BA 'For Each' loop with an internal 'Condition' task to filter each indicator.
  3. CA 'Condition' task with a complex JQ expression to filter the list and branch.
  4. DA 'Script' task that uses Python to filter the list and then outputs the filtered list.
Show answer & explanation

Correct answer: D. A 'Script' task that uses Python to filter the list and then outputs the filtered list.

While 'For Each' with conditions can work, for complex filtering logic on a list, using a 'Script' task (Python) is generally more efficient and readable. The script can perform the filtering and then output the refined list, which can then be easily consumed by a subsequent 'For Each' loop or other tasks.

Why the other options are wrong

  • A. A 'For Each' loop with an *internal* script to filter is less efficient; it's better to filter the entire list once with a script, then iterate over the *filtered* list.
  • B. Filtering within a 'For Each' loop using a 'Condition' task is possible but can make the playbook visual flow cluttered and less efficient for complex filtering operations.
  • C. While JQ is powerful, embedding complex JQ expressions directly into a 'Condition' task can make it harder to read, debug, and maintain compared to a Python script, especially for multiple filtering criteria.

Script-Based List Filtering

Utilizing a Python script within a playbook to perform complex filtering operations on lists of data (e.g., indicators, incidents) before further processing, enhancing efficiency and readability over multiple conditional tasks.

  • Ideal for multi-criteria or complex filtering logic.
  • More efficient than sequential conditional checks in loops.
  • Outputs a clean, filtered list for subsequent tasks.

Memory trick: To pick the best items, use a script to sort the whole basket first.

More Playbooks questions