Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy

A security analyst is developing a custom integration for Cortex XSOAR that interacts with an internal API. The API requires a specific `Client-ID` header to be sent with every request, but the value for this header changes frequently based on the environment (development, staging, production). How should the analyst configure this in the integration to allow for easy updates without modifying the integration code?

  1. AUse a playbook input to pass the `Client-ID` to each command call.
  2. BHardcode the `Client-ID` in the integration's Python script.
  3. CDefine the `Client-ID` as an integration instance parameter.
  4. DStore the `Client-ID` in a XSOAR global credential object.
Show answer & explanation

Correct answer: C. Define the `Client-ID` as an integration instance parameter.

Integration instance parameters are designed for configurable values that can change per instance or environment. This allows the `Client-ID` to be set during integration instance creation or modification without touching the code.

Why the other options are wrong

  • A. Using playbook inputs for a value required by *every* request is cumbersome and not the intended use for integration-wide configuration.
  • B. Hardcoding requires code changes and redeployment for every update, which is inefficient.
  • D. Global credentials are for sensitive data like passwords or API keys, not typically for frequently changing, non-secret identifiers.

Integration Instance Parameters

Configurable values defined within an integration's YAML file that can be set or modified per integration instance, allowing customization without altering the underlying code.

  • Allow customization per integration instance.
  • Configured in the integration's YAML.
  • Accessible within the integration script via `demisto.params()`.

Memory trick: Parameters Power Personalized Plugins.

More Integrations questions