Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security engineer is tasked with migrating an existing custom integration from a development XSOAR environment to a production environment. The integration relies on several external Python libraries that are not bundled with the standard XSOAR platform. Which of the following is the MOST appropriate method to ensure these external libraries are available and correctly used in the production environment?

  1. AInclude the libraries in the integration's ZIP file under a `dist` folder.
  2. BManually install the libraries on the XSOAR server's operating system.
  3. CCopy the library files directly into the XSOAR content pack directory.
  4. DUse the `dockerimage` field in the integration YAML to specify a custom Docker image.
Show answer & explanation

Correct answer: D. Use the `dockerimage` field in the integration YAML to specify a custom Docker image.

For custom integrations requiring external Python libraries not natively available, specifying a custom Docker image via the `dockerimage` field in the integration's YAML is the recommended and most robust method. This ensures a consistent, isolated, and pre-configured environment with all necessary dependencies.

Why the other options are wrong

  • A. While some integrations use `dist` for small, internal modules, it's not the standard or scalable way to manage external, complex Python library dependencies for custom integrations.
  • B. Manually installing libraries on the OS is error-prone, not scalable, and can lead to dependency conflicts, especially in containerized environments.
  • C. Copying files directly into the content pack directory is not a standard or maintainable way to manage external Python dependencies and can cause issues with upgrades and content integrity.

Custom Integration External Dependencies

Python libraries or other software components not natively included with Cortex XSOAR that are required for a custom integration to function.

  • Best managed using custom Docker images.
  • Ensures isolated and reproducible environments.
  • Prevents dependency conflicts on the XSOAR server.

Memory trick: Dependencies need Docker, not manual installs.

More Integrations questions