Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard
A security analyst is developing a playbook that retrieves a list of indicators from a threat intelligence platform. The playbook then needs to filter this list to only include indicators that are of type 'IP' and have a 'severity' greater than 'medium'. After filtering, a sub-playbook should be called for each of these filtered indicators. Which playbook construct and context manipulation method should be used to achieve this filtering efficiently?
- AA 'For Each' loop with a custom 'Script' task to filter and then call the sub-playbook.
- BA 'For Each' loop with an internal 'Condition' task to filter each indicator.
- CA 'Condition' task with a complex JQ expression to filter the list and branch.
- DA 'Script' task that uses Python to filter the list and then outputs the filtered list.
Show answer & explanationAnswer & explanation
Correct answer: D. A 'Script' task that uses Python to filter the list and then outputs the filtered list.
While 'For Each' with conditions can work, for complex filtering logic on a list, using a 'Script' task (Python) is generally more efficient and readable. The script can perform the filtering and then output the refined list, which can then be easily consumed by a subsequent 'For Each' loop or other tasks.
Why the other options are wrong
- A. A 'For Each' loop with an *internal* script to filter is less efficient; it's better to filter the entire list once with a script, then iterate over the *filtered* list.
- B. Filtering within a 'For Each' loop using a 'Condition' task is possible but can make the playbook visual flow cluttered and less efficient for complex filtering operations.
- C. While JQ is powerful, embedding complex JQ expressions directly into a 'Condition' task can make it harder to read, debug, and maintain compared to a Python script, especially for multiple filtering criteria.
Script-Based List Filtering
Utilizing a Python script within a playbook to perform complex filtering operations on lists of data (e.g., indicators, incidents) before further processing, enhancing efficiency and readability over multiple conditional tasks.
- Ideal for multi-criteria or complex filtering logic.
- More efficient than sequential conditional checks in loops.
- Outputs a clean, filtered list for subsequent tasks.
Memory trick: To pick the best items, use a script to sort the whole basket first.