Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security analyst is developing a custom integration for Cortex XSOAR that needs to interact with an internal data source. The data source's API uses a custom HTTP header, `X-Data-Source-Auth`, which requires a dynamically generated token based on the current timestamp and a pre-shared secret. This token must be regenerated for every single API call. How can this dynamic header be most efficiently managed within the integration's Python code?

  1. AStore the pre-shared secret in `demisto.params()` and generate the token in each command.
  2. BOverride the `_http_request` method in the `Client` class to inject the dynamic header.
  3. CPass the dynamically generated token as a separate argument to each command function.
  4. DDefine the header in the `headers` attribute of the `BaseClient` instance.
Show answer & explanation

Correct answer: B. Override the `_http_request` method in the `Client` class to inject the dynamic header.

Overriding the `_http_request` method of the `BaseClient` is the most efficient and centralized way to manage headers that need to be dynamically generated for *every* API call. This ensures the logic for token generation and header injection is in one place and automatically applied to all requests without duplicating code in each command function.

Why the other options are wrong

  • A. Storing the secret in `demisto.params()` is appropriate, but generating the token in each command function leads to code duplication. The question asks for *efficient management*.
  • C. Passing the token as an argument to each command function requires redundant token generation and passing logic across multiple functions.
  • D. The `headers` attribute of `BaseClient` is for static headers, not for headers that need to be dynamically generated per request.

Dynamic Header Injection via `_http_request`

Overriding the `_http_request` method in a custom integration's `Client` class to dynamically generate and inject custom HTTP headers into every outgoing API request, ensuring real-time values for authentication or other purposes.

  • Centralizes dynamic header generation.
  • Ensures headers are fresh for every request.
  • Avoids code duplication in command functions.

Memory trick: Override the request to dynamically stamp every outgoing letter.

More Integrations questions