Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security architect is designing a new custom integration for Cortex XSOAR that needs to interact with an external cloud service. The cloud service generates short-lived, encrypted session tokens that are valid for only 5 minutes. The integration will make multiple API calls over a longer period. To avoid repetitive authentication and ensure continuous operation, what is the most efficient method for the integration to handle these tokens?

  1. AIncrease the `command_timeout` parameter to allow more time for token acquisition.
  2. BStore the token in a global variable and refresh it only when an API call fails due to invalid token.
  3. CImplement a token refresh mechanism that proactively obtains a new token just before the current one expires.
  4. DRe-authenticate and obtain a new token for every API call.
Show answer & explanation

Correct answer: C. Implement a token refresh mechanism that proactively obtains a new token just before the current one expires.

For short-lived tokens, a proactive token refresh mechanism is the most efficient and robust approach. The integration should track the token's expiry time and automatically request a new token a short period before the current one expires, ensuring that subsequent API calls always use a valid token without interruption or relying on reactive failure handling.

Why the other options are wrong

  • A. Increasing `command_timeout` addresses command execution time, not token validity or refresh logic.
  • B. Reactively refreshing only after failure introduces latency and potential command failures, leading to a less reliable integration.
  • D. Re-authenticating for every call is highly inefficient due to overhead and potential rate limits on authentication endpoints.

Proactive Token Refresh

An integration strategy where short-lived access tokens are automatically renewed just before their expiration, preventing service interruptions.

  • Ensures continuous operation with short-lived tokens.
  • Avoids reactive error handling (e.g., re-authenticating after failure).
  • Requires tracking token expiry time.

Memory trick: Don't wait for the token to die; renew it before it flies!

More Integrations questions