Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is developing a custom integration for Cortex XSOAR that needs to create and update incidents in a third-party ticketing system. The ticketing system's API requires a unique identifier (e.g., a ticket ID) to be extracted from the creation response and then used in subsequent update requests. How should the integration store and retrieve this unique identifier to ensure it's available for later commands within the same incident context?

  1. AStore the ID in the incident context (`demisto.setContext()`) and retrieve it with `demisto.getContext()`.
  2. BWrite the ID to a temporary file on the XSOAR engine's filesystem.
  3. CReturn the ID as a `CommandResults` object to the War Room, then manually copy-paste for subsequent commands.
  4. DStore the ID in a global Python variable within the integration code.
Show answer & explanation

Correct answer: A. Store the ID in the incident context (`demisto.setContext()`) and retrieve it with `demisto.getContext()`.

The incident context (`demisto.setContext()` and `demisto.getContext()`) is the primary mechanism in Cortex XSOAR for storing and retrieving temporary data that needs to persist across different commands and playbooks within the scope of a single incident. This ensures the unique identifier is available for subsequent operations related to that specific incident.

Why the other options are wrong

  • B. Writing to the filesystem is generally not recommended for temporary data sharing in XSOAR, as it can lead to cleanup issues and is not context-aware across incidents.
  • C. Manually copying from the War Room defeats automation and is not a programmatic solution for integration interaction.
  • D. Global Python variables are ephemeral and tied to the execution of a single command, not persistent across different commands or incidents.

Incident Context (`demisto.setContext`)

A mechanism in Cortex XSOAR to store and retrieve data that persists throughout the lifecycle of a specific incident, accessible by various commands and playbooks.

  • Stores key-value pairs associated with an incident.
  • Data persists across commands and playbook runs.
  • Accessed via `demisto.setContext()` and `demisto.getContext()`.
  • Essential for sharing data between integration commands.

Memory trick: Context is the incident's memory, set it and forget it (until you need it).

More Integrations questions