Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy

A security engineer is developing a custom integration for Cortex XSOAR that interacts with a network device. The device's API returns large amounts of data in its responses, and the engineer wants to ensure that the raw JSON output from a specific command is always preserved in the War Room for forensic analysis, even if the integration's `return_outputs()` function only extracts a subset of the fields. Which `CommandResults` parameter should be used to achieve this?

  1. A`entry_type`
  2. B`outputs`
  3. C`readable_output`
  4. D`raw_response`
Show answer & explanation

Correct answer: D. `raw_response`

The `raw_response` parameter of `CommandResults` is specifically designed to store the complete, unparsed, raw response from an API call in the War Room. This ensures that the full JSON data is preserved for review, regardless of what structured data is extracted for `outputs` or `readable_output`.

Why the other options are wrong

  • A. `entry_type` defines the type of War Room entry (e.g., `note`, `error`), not its content.
  • B. `outputs` is for structured data that updates incident context and can be used in playbooks, but it doesn't necessarily store the entire raw API response.
  • C. `readable_output` is for user-friendly text displayed in the War Room, not for preserving raw JSON.

CommandResults `raw_response`

The `raw_response` parameter in `CommandResults` is used to store the complete, original API response as a file in the War Room, ensuring full data preservation.

  • Preserves the entire raw API response (e.g., JSON, XML).
  • Stored as a file attachment in the War Room.
  • Useful for auditing, debugging, and forensic analysis.
  • Independent of `outputs` and `readable_output`.

Memory trick: Raw response for the full, untouched package.

More Integrations questions