Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security engineer is troubleshooting a custom integration where a specific command, `get-user-details`, intermittently fails with a network timeout error, while other commands in the same integration function correctly. The `get-user-details` command connects to an internal LDAP server that is sometimes slow to respond. What is the most targeted approach to resolve the timeout issue for *only* this specific command without affecting the timeout settings of other commands or the entire integration instance?
- AConfigure a global network timeout setting on the Cortex XSOAR engine.
- BModify the Python code of the `get-user-details` command to include a higher timeout value in its API call.
- CAdd a `sleep` function before calling `get-user-details` in the playbook.
- DIncrease the 'Command Timeout' setting for the entire integration instance.
Show answer & explanationAnswer & explanation
Correct answer: B. Modify the Python code of the `get-user-details` command to include a higher timeout value in its API call.
Modifying the Python code for the specific command to set a higher timeout value for its API call is the most targeted and effective solution. This allows granular control over the timeout for that particular operation without impacting other commands or the overall integration instance, which might have different performance requirements.
Why the other options are wrong
- A. A global network timeout on the XSOAR engine would affect all integrations and commands, which is too broad for a specific command's issue.
- C. Adding a `sleep` function in the playbook doesn't resolve the timeout of the API call itself; it only delays when the command is *called*, not how long it waits for a response.
- D. Increasing the instance-wide 'Command Timeout' would affect all commands, potentially delaying faster commands unnecessarily or masking issues with other commands.
Command-Specific Timeout
To address timeout issues for a specific integration command, the timeout value should be configured directly within the command's Python code where the API call is made.
- Granular control over command execution.
- Prevents affecting other commands/instance.
- Implemented in the Python script's API call.
Memory trick: Timeouts can be broad or 'targeted' like a sniper.