Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsHard

A security architect is designing the network topology for an on-premises Cortex XSOAR deployment that uses multiple XSOAR Engines in a DMZ to communicate with external integrations. The main XSOAR server is located in an internal, highly secured network segment. Which network port must be opened outbound from the XSOAR Engines to the main XSOAR server for proper communication and command execution?

  1. ATCP 443 (HTTPS)
  2. BTCP 8080 (HTTP Proxy)
  3. CTCP 22 (SSH)
  4. DUDP 514 (Syslog)
Show answer & explanation

Correct answer: A. TCP 443 (HTTPS)

Cortex XSOAR Engines communicate with the main XSOAR server over HTTPS (TCP 443). This is the standard secure communication channel for engines to receive commands, send results, and synchronize content with the server.

Why the other options are wrong

  • B. TCP 8080 is a common port for HTTP proxies or other services, but not the primary communication port for XSOAR Engines to the server.
  • C. SSH (TCP 22) is used for secure shell access, not for regular engine-to-server communication.
  • D. UDP 514 is for Syslog, which is used for logging, not for engine operational communication with the server.

XSOAR Engine Communication Port

The standard network port used by Cortex XSOAR Engines to securely communicate with the main XSOAR server.

  • TCP port 443 is used.
  • Communication is over HTTPS for security.
  • Engines initiate outbound connections to the server.

Memory trick: Think of XSOAR components 'talking' to each other through well-defined, secure 'doors' (ports).

More Cortex XSOAR Fundamentals questions