Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security engineer is developing a custom integration in Cortex XSOAR that interacts with a legacy system's API. This API requires a custom HTTP header, `X-Legacy-Token`, with a specific value for every request. The engineer needs to ensure this header is consistently included in all API calls made by the integration. Where is the most appropriate place to define this custom header within the Python integration code?
- AAs a parameter in the integration instance configuration.
- BAs a global variable in the `demisto_handle_args` function.
- CHardcoded directly into each individual API call method.
- DWithin the `__init__` method of the integration's client class.
Show answer & explanationAnswer & explanation
Correct answer: D. Within the `__init__` method of the integration's client class.
Defining the custom header within the `__init__` method of the integration's client class allows it to be consistently added to the `requests` session or client object used for all subsequent API calls. This centralizes the header management and ensures it's applied to every request without needing to hardcode it repeatedly.
Why the other options are wrong
- A. While the *value* might come from configuration, the *definition* and *application* of the header to the client should be in the client class `__init__`.
- B. Global variables within `demisto_handle_args` are not suitable for client-level persistent HTTP headers.
- C. Hardcoding into each method is inefficient, error-prone, and makes maintenance difficult.
Custom HTTP Headers in Integrations
HTTP headers required by external APIs that need to be consistently sent with every request from an XSOAR integration.
- Often used for authentication, custom tracking, or API versioning.
- Best defined once in the client or session object.
- Centralized management improves maintainability and reduces errors.
Memory trick: Client's init sets the stage for all API requests.