Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium
A security automation engineer is debugging a playbook that is failing at a specific script task. The script takes an IP address as input, but the playbook context shows that the IP address being passed to the script is empty, even though a previous enrichment task successfully identified it. What is the most likely cause for the empty input to the script?
- AThe script has a syntax error that prevents it from reading any input.
- BThe IP address is being stored in a local variable within the previous task, not in the playbook context.
- CThe previous enrichment task's output key for the IP address is misspelled or incorrect.
- DThe playbook is configured to run the script before the enrichment task completes.
Show answer & explanationAnswer & explanation
Correct answer: C. The previous enrichment task's output key for the IP address is misspelled or incorrect.
A common mistake when passing data via context is a mismatch in keys. If the script expects 'IP.Address' but the enrichment task outputs to 'ipaddress', the script will receive an empty value, even if the data exists in context under a different key.
Why the other options are wrong
- A. A syntax error in the script would likely cause the script to fail execution, not just receive an empty input when data is available.
- B. Data in playbook tasks is generally written to the playbook context (unless explicitly handled otherwise by a script not writing to context), so 'local variable' isn't the primary issue here; rather, it's how that context data is referenced.
- D. If the script were running before the enrichment, the enrichment task would not have completed, and its output wouldn't be available at all, leading to a different error or behavior.
Context Path Mismatch
A context path mismatch occurs when a playbook task or script attempts to retrieve data from the playbook context using an incorrect or misspelled key (path), resulting in the retrieval of an empty or null value.
- Common debugging issue.
- Requires careful review of context outputs and input arguments.
- Tools like 'Context Browser' help identify correct paths.
Memory trick: Keys Must Match Context's Core.