Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium
A security orchestration engineer is designing a playbook to automate the initial triage of security incidents. The playbook needs to execute a specific set of tasks (e.g., enrich indicators, check reputation) only if the incident type is 'Phishing'. What is the most efficient way to implement this conditional execution using a playbook task?
- AUse an 'If-Else' script within a single task.
- BSet a DQL query in the 'Pre-condition' of each task.
- CPlace the tasks inside a sub-playbook and call it conditionally.
- DUse a 'Condition' task to branch the playbook execution.
Show answer & explanationAnswer & explanation
Correct answer: D. Use a 'Condition' task to branch the playbook execution.
A 'Condition' task is specifically designed for branching playbook execution based on criteria, making it the most direct and readable way to implement conditional logic like 'only if incident type is Phishing'. It provides a clear visual representation of the different execution paths.
Why the other options are wrong
- A. An 'If-Else' script could work but is less visually clear and harder to maintain for complex branching than a Condition task.
- B. Setting a 'Pre-condition' on *each* task is redundant and inefficient, as the condition only needs to be checked once to branch the flow.
- C. Calling a sub-playbook conditionally is an option, but a 'Condition' task is more direct for simple branching within the main playbook.
Playbook Condition Task
A 'Condition' task in Cortex XSOAR playbooks allows for dynamic branching of the playbook's execution path based on specified criteria, often derived from incident context or previous task outputs.
- Enables 'if/then/else' logic within a playbook.
- Uses DQL (Demisto Query Language) for defining conditions.
- Creates clear, visual branches for different scenarios.
Memory trick: Conditions are the traffic lights of your playbook, directing flow based on incident data.