Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy
A security engineer is developing a custom integration for Cortex XSOAR that interacts with a partner's API. The integration needs to be flexible enough to connect to different environments (e.g., development, staging, production) of the partner's API, each with a distinct base URL. How should the engineer design the integration to allow users to easily switch between these environments without modifying the integration code?
- AUse environment variables on the XSOAR server to store the base URL for each environment.
- BRequire users to manually edit the integration's Python file to change the base URL for each environment.
- CDefine the base URL as an integration instance parameter, allowing users to input it during instance creation.
- DHardcode all possible base URLs in the integration code and use a conditional statement to select one.
Show answer & explanationAnswer & explanation
Correct answer: C. Define the base URL as an integration instance parameter, allowing users to input it during instance creation.
To allow users to easily switch between different API environments, the base URL should be defined as a configurable integration instance parameter. This enables users to input the specific URL during instance creation or modification, without touching the code.
Why the other options are wrong
- A. While environment variables can be used, integration parameters are the native and more user-friendly way within Cortex XSOAR to expose configurable options to the end-user.
- B. Requiring manual code edits is highly impractical, error-prone, and violates secure operational practices for integrations.
- D. Hardcoding URLs makes the integration inflexible and requires code changes for new environments, which is against best practices for configurable integrations.
Configurable Base URL
A configurable base URL for an integration allows users to specify the target API endpoint (e.g., development, staging, production) as an integration instance parameter, making the integration flexible and reusable across different environments.
- Defined as an integration parameter in the YAML.
- Users input the URL during instance creation.
- Enables connecting to different API environments without code changes.
Memory trick: Parameters for Paths, Not Code.