Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security automation engineer is debugging a playbook that is failing at a specific script task. The script takes an IP address as input, but the playbook context shows that the IP address being passed to the script is empty, even though a previous enrichment task successfully identified it. What is the most likely cause for the empty input to the script?

  1. AThe script has a syntax error that prevents it from reading any input.
  2. BThe IP address is being stored in a local variable within the previous task, not in the playbook context.
  3. CThe previous enrichment task's output key for the IP address is misspelled or incorrect.
  4. DThe playbook is configured to run the script before the enrichment task completes.
Show answer & explanation

Correct answer: C. The previous enrichment task's output key for the IP address is misspelled or incorrect.

A common mistake when passing data via context is a mismatch in keys. If the script expects 'IP.Address' but the enrichment task outputs to 'ipaddress', the script will receive an empty value, even if the data exists in context under a different key.

Why the other options are wrong

  • A. A syntax error in the script would likely cause the script to fail execution, not just receive an empty input when data is available.
  • B. Data in playbook tasks is generally written to the playbook context (unless explicitly handled otherwise by a script not writing to context), so 'local variable' isn't the primary issue here; rather, it's how that context data is referenced.
  • D. If the script were running before the enrichment, the enrichment task would not have completed, and its output wouldn't be available at all, leading to a different error or behavior.

Context Path Mismatch

A context path mismatch occurs when a playbook task or script attempts to retrieve data from the playbook context using an incorrect or misspelled key (path), resulting in the retrieval of an empty or null value.

  • Common debugging issue.
  • Requires careful review of context outputs and input arguments.
  • Tools like 'Context Browser' help identify correct paths.

Memory trick: Keys Must Match Context's Core.

More Playbooks questions