Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security analyst is troubleshooting a custom integration in Cortex XSOAR that interacts with a cloud-based service. The integration intermittently fails with `SSL: CERTIFICATE_VERIFY_FAILED` errors. The cloud service uses a valid, publicly trusted SSL certificate. The XSOAR engine is self-hosted in an air-gapped environment. What is the MOST likely root cause of this certificate verification failure?
- AThe API endpoint URL for the cloud service is incorrect.
- BThe integration's API key has expired, causing authentication issues.
- CThe XSOAR engine's operating system is missing trusted root CA certificates.
- DA network firewall is blocking the HTTPS traffic to the cloud service.
Show answer & explanationAnswer & explanation
Correct answer: C. The XSOAR engine's operating system is missing trusted root CA certificates.
In an air-gapped or isolated environment, the operating system of the self-hosted XSOAR engine might not have up-to-date or complete trusted root CA certificates. When the integration tries to establish an SSL connection, it cannot verify the cloud service's certificate chain against its local trust store, leading to `CERTIFICATE_VERIFY_FAILED` errors.
Why the other options are wrong
- A. An incorrect URL would likely result in a connection error (e.g., hostname not found) or a 404, not specifically an SSL certificate verification failure.
- B. An expired API key would cause an authentication error (e.g., 401 Unauthorized) after the SSL handshake, not a `CERTIFICATE_VERIFY_FAILED` during the handshake.
- D. A firewall blocking HTTPS traffic would result in a connection refused or timeout error, not a specific SSL certificate verification failure message, which implies the connection was at least partially established to attempt verification.
SSL Certificate Verification Failure
An error occurring during the SSL/TLS handshake when a client (e.g., XSOAR engine) cannot validate the server's identity based on its trusted certificate authority (CA) store.
- Often indicates missing or outdated root CA certificates on the client.
- Common in isolated or air-gapped environments.
- Different from network blocking or authentication errors.
Memory trick: SSL errors mean trust issues, check the certificates.