Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that interacts with a third-party API. The API requires a dynamic signature generated using a private key and a specific algorithm for each request. This signature must be included in a custom HTTP header. Which integration parameter type is most suitable for securely storing the private key required for signature generation?

  1. AShort Text
  2. BBoolean
  3. CEncrypted
  4. DCredential
Show answer & explanation

Correct answer: C. Encrypted

The 'Encrypted' parameter type in Cortex XSOAR is specifically designed for storing sensitive information like private keys, API secrets, or certificates securely. It ensures that the value is encrypted at rest and only decrypted when the integration needs to use it, providing a higher level of security than other parameter types for such critical data.

Why the other options are wrong

  • A. Short Text stores data in plain text, making it unsuitable for sensitive private keys.
  • B. Boolean parameters store true/false values and are irrelevant for storing a private key string.
  • D. Credential is used for username/password pairs or API keys, but not typically for raw private keys that require encryption at rest.

Encrypted Integration Parameter

An integration parameter type in Cortex XSOAR designed to securely store sensitive data by encrypting it at rest.

  • Encrypts data at rest.
  • Decrypts data at runtime for use by the integration.
  • Ideal for private keys, API secrets, and sensitive tokens.

Memory trick: Encrypting secrets keeps API keys safe with a digital lock.

More Integrations questions