Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security engineer is developing a custom integration that interacts with a network device's API. The API returns a large amount of raw configuration data in a plain text format. The engineer wants to ensure that when a command from this integration is executed in the War Room, the raw, unformatted text response is displayed directly for easy review without any additional parsing or formatting by XSOAR. Which output method should be used for the command's results?
- A`return_results(human_readable='...')`
- B`return_results(raw_response='...')`
- C`return_results(contents_format=EntryFormat.MARKDOWN, contents='...')`
- D`return_results(file_result='...')`
Show answer & explanationAnswer & explanation
Correct answer: B. `return_results(raw_response='...')`
To display raw, unformatted text directly in the War Room, the `raw_response` parameter within `return_results()` is the most appropriate. This tells XSOAR to take the provided string and render it as-is, without attempting to interpret it as Markdown, JSON, or any other structured format, which is ideal for raw configuration data.
Why the other options are wrong
- A. `human_readable` is for displaying formatted, user-friendly output, not raw text.
- C. `contents_format=EntryFormat.MARKDOWN` would attempt to parse and render the text as Markdown, which is not desired for raw, unformatted output.
- D. `file_result` is for attaching a file to the War Room entry, not for displaying the raw text inline.
War Room Raw Output (`raw_response`)
A `return_results()` parameter in Cortex XSOAR integrations used to display raw, unformatted text directly in the War Room entry.
- Renders text as-is, without parsing or formatting.
- Ideal for raw logs, configuration data, or unformatted API responses.
- Ensures exact content visibility for review.
- Distinct from `human_readable` (formatted) or `contents` (structured).
Memory trick: For raw data, just 'raw_response' it; no need to dress it up.