Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy

A security engineer is developing a custom integration for Cortex XSOAR that interacts with a proprietary API. The API requires a unique API key to be included in the `Authorization` header for every request. This API key is sensitive and must not be exposed in logs or configuration files. Which of the following is the MOST secure and recommended method to handle this API key within the custom integration?

  1. AHardcode the API key directly into the Python code of the integration.
  2. BStore the API key as a secure integration instance parameter and access it using `demisto.params().get('api_key')`.
  3. CRetrieve the API key from an environment variable set on the Cortex XSOAR engine.
  4. DEmbed the API key in a separate configuration file and load it at runtime.
Show answer & explanation

Correct answer: B. Store the API key as a secure integration instance parameter and access it using `demisto.params().get('api_key')`.

Storing sensitive credentials like API keys as secure integration instance parameters is the most secure method in Cortex XSOAR. This ensures the key is encrypted at rest and only accessible by the integration at runtime, preventing exposure in plaintext.

Why the other options are wrong

  • A. Hardcoding exposes the key in source code, making it highly insecure and difficult to manage.
  • C. Environment variables can be viewed by system administrators and are not encrypted by XSOAR, making them less secure than dedicated secure parameters.
  • D. A separate configuration file can still be read by unauthorized users or exposed if not properly secured, failing to meet the requirement for encryption and secure handling.

Secure Integration Parameters

Cortex XSOAR integration parameters marked as 'secure' are encrypted in the database and masked in UI/logs, providing a secure way to store sensitive credentials.

  • Encrypts sensitive values at rest.
  • Masks values in UI and logs.
  • Accessed programmatically via `demisto.params().get()`.
  • Prevents accidental exposure of credentials.

Memory trick: Secure Parameters Protect Private Keys.

More Integrations questions