Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security engineer is developing a custom integration in Cortex XSOAR that interacts with a secure internal API. The internal API requires that all requests include a specific HTTP header, `X-API-Tenant-ID`, with a unique tenant identifier. Where should this custom header be configured within the integration to ensure it is automatically sent with every API call made by the integration's HTTP client?
- AHardcoded into every `requests.get()` or `requests.post()` call in the Python script.
- BDefined as a global variable in the XSOAR server settings.
- CPassed as an argument to the `demisto.results()` function.
- DAdded to the `http_headers` parameter in the integration instance configuration.
Show answer & explanationAnswer & explanation
Correct answer: D. Added to the `http_headers` parameter in the integration instance configuration.
Cortex XSOAR integration instances provide a `http_headers` parameter (or similar, depending on the integration base) where custom HTTP headers can be defined. These headers are then automatically included in all API calls made by the integration's HTTP client, ensuring consistency and central management.
Why the other options are wrong
- A. Hardcoding headers into every call is inefficient, error-prone, and makes updates difficult.
- B. Global variables are not the appropriate mechanism for configuring integration-specific HTTP headers and lack fine-grained control.
- C. `demisto.results()` is for returning output to the War Room or context, not for configuring outgoing HTTP requests.
Integration Custom HTTP Headers
HTTP headers configured at the integration instance level in Cortex XSOAR that are automatically included in all outgoing API requests made by that integration.
- Configured in the integration instance settings (e.g., `http_headers` parameter).
- Ensures consistent header inclusion across all API calls.
- Centralizes management of necessary request headers.
Memory trick: Headers belong in config, not code or globals.