Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksEasy

A security analyst is developing a playbook in Cortex XSOAR to automate the initial triage of security incidents. They need to ensure that a specific script task, which performs a critical API call, always executes, even if previous non-critical tasks in the same branch fail. Which task property should be configured for the critical API call script task?

  1. AForce Run
  2. BContinue On Error
  3. CAlways Execute
  4. DIs Critical
Show answer & explanation

Correct answer: C. Always Execute

The 'Always Execute' task property ensures that a task runs regardless of the outcome of previous tasks in its execution path, which is crucial for critical operations that must proceed even if unrelated parts of the playbook encounter issues. The other options do not provide this specific functionality.

Why the other options are wrong

  • A. 'Force Run' is not a standard task property in Cortex XSOAR for this purpose.
  • B. 'Continue On Error' allows the playbook to proceed when *this* task fails, not when a *previous* one fails.
  • D. 'Is Critical' marks a task as important, but doesn't force its execution if a preceding task fails.

Always Execute Task Property

The 'Always Execute' task property in Cortex XSOAR ensures that a specific task will always be executed, even if a preceding task in the same branch of the playbook fails.

  • Guarantees execution regardless of prior failures.
  • Useful for critical cleanup, notification, or essential data collection tasks.
  • Overrides the default behavior of stopping a branch on error.

Memory trick: Always Execute is your safety net for critical operations, like a 'show must go on' for tasks.

More Playbooks questions