Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that needs to interact with a proprietary API that uses a unique authentication mechanism. Instead of standard API keys or OAuth, the API requires a custom-generated signature based on the request payload and a shared secret. Which `BaseClient` method should the engineer override or extend to inject this signature into each request?

  1. A`get_headers()`
  2. B`build_url()`
  3. C`_http_request()`
  4. D`test_module()`
Show answer & explanation

Correct answer: C. `_http_request()`

To implement a unique, custom authentication mechanism that depends on the request payload, the `_http_request()` method within the `BaseClient` should be overridden. This method provides direct control over the request before it is sent, allowing for dynamic header or body manipulation.

Why the other options are wrong

  • A. `get_headers()` is used to retrieve existing headers, not to dynamically generate and inject a signature based on the request payload.
  • B. `build_url()` is used to construct the request URL, not to manage headers or authentication signatures.
  • D. `test_module()` is for validating integration connectivity and credentials, not for handling request-specific authentication logic.

Overriding _http_request()

The `_http_request()` method in Cortex XSOAR's `BaseClient` can be overridden to implement custom logic for HTTP requests, such as injecting dynamic authentication headers, modifying the request body, or handling specific HTTP behaviors.

  • Provides granular control over HTTP request creation.
  • Essential for complex or custom authentication schemes.
  • Allows modification of headers, URL, method, and body before sending.

Memory trick: Override `_http_request` to Craft Unique Connections.

More Integrations questions