Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that interacts with a cloud-based security service. The service's API requires an API key and a secret, which are provided by the user during integration instance configuration. Additionally, the integration needs a configurable base URL (e.g., `https://api.example.com/v1` or `https://qa.example.com/v1`) and a boolean flag to enable debug logging. How should these configuration items be defined in the integration's YAML file to ensure they are properly presented and managed in the Cortex XSOAR UI?

  1. AStore them directly in the `params` dictionary within the integration's `__init__` function.
  2. BDefine them as global constants in the Python code.
  3. CUse `demisto.params().get()` to retrieve values from environment variables.
  4. DAdd them to the `configuration` section of the integration's YAML file with appropriate `type` and `display` properties.
Show answer & explanation

Correct answer: D. Add them to the `configuration` section of the integration's YAML file with appropriate `type` and `display` properties.

The `configuration` section in the integration's YAML file is where all user-configurable parameters for an integration instance are defined. This allows Cortex XSOAR to automatically generate the UI fields for users to input values, including sensitive data, base URLs, and boolean flags, ensuring proper display and management.

Why the other options are wrong

  • A. The `params` dictionary is populated by Cortex XSOAR based on the YAML configuration; directly storing values here bypasses the configuration mechanism.
  • B. Global constants prevent user configuration and are not suitable for dynamic settings or sensitive credentials.
  • C. While environment variables can be used, defining parameters in the YAML provides a user-friendly UI for configuration within XSOAR and better integration with its secure parameter handling for sensitive data.

Integration Configuration YAML

The `configuration` section in a Cortex XSOAR integration's YAML file defines the parameters that users can set when creating an integration instance, generating the UI for these settings.

  • Defines all user-configurable parameters.
  • Uses `type` (e.g., `string`, `boolean`, `Credential`) and `display` properties.
  • Automatically generates UI fields for instance creation.
  • Supports secure types for sensitive data like API keys.

Memory trick: YAML configuration controls the UI's parameters.

More Integrations questions