Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security engineer is developing a custom integration that interacts with an external service requiring client certificate authentication (mTLS). The service provides a client certificate file (`client.crt`) and a corresponding private key file (`client.key`). How should these files be configured within the Cortex XSOAR integration instance to enable successful mTLS?

  1. AUpload `client.crt` to the 'Trusted Certificate' store and `client.key` to an 'Encrypted' parameter.
  2. BEmbed the contents of both `client.crt` and `client.key` directly into a 'Long Text' parameter.
  3. CCombine `client.crt` and `client.key` into a single PFX/P12 file and upload it to a dedicated 'Client Certificate' parameter.
  4. DUpload `client.crt` to the 'SSL Certificate' parameter and `client.key` to the 'SSL Certificate Key' parameter.
Show answer & explanation

Correct answer: D. Upload `client.crt` to the 'SSL Certificate' parameter and `client.key` to the 'SSL Certificate Key' parameter.

Cortex XSOAR integration instances typically provide separate dedicated parameters for client SSL certificates and their corresponding private keys, often named 'SSL Certificate' and 'SSL Certificate Key' (or similar). These parameters are designed to securely store and utilize the certificate and key pair for mTLS, ensuring they are correctly presented during the TLS handshake.

Why the other options are wrong

  • A. The 'Trusted Certificate' store is for server certificates (to verify the server), not for the client's own certificate. The key needs to be paired with its certificate.
  • B. Embedding sensitive keys in 'Long Text' is insecure and not the expected format for mTLS configuration, which requires specific file handling.
  • C. While combining into PFX/P12 is a common practice, XSOAR usually provides separate fields for the `.crt` and `.key` files, or a dedicated parameter expecting a single PEM-encoded block containing both, rather than a PFX/P12 file directly for client certificates (unless specified by the integration). Separate fields are more common and flexible.

Client Certificate (mTLS) Configuration

Configuring an XSOAR integration with a client certificate and private key to perform mutual TLS (mTLS) authentication with an external service.

  • Requires both a client certificate (`.crt`) and its private key (`.key`).
  • Files are typically uploaded to dedicated integration parameters.
  • Enables the client (XSOAR) to authenticate to the server.
  • Distinct from server certificate verification (which uses trusted CAs).

Memory trick: Client's cert and key go hand-in-hand to unlock the server door.

More Integrations questions