Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security analyst is developing a custom integration for Cortex XSOAR that needs to perform a series of actions on an external system. These actions involve multiple API calls that require an authentication token. The token has a short expiry time (e.g., 15 minutes) and must be refreshed automatically before each operation if it's expired or close to expiration. What is the most efficient way to manage and refresh this token within the custom integration?

  1. AFetch a new token at the beginning of every command execution.
  2. BStore the token in a global variable and refresh it once daily using a scheduled job.
  3. CManually update the integration instance with a new token whenever it expires.
  4. DImplement a `get_token()` helper function that checks token validity and refreshes it if needed before making API calls.
Show answer & explanation

Correct answer: D. Implement a `get_token()` helper function that checks token validity and refreshes it if needed before making API calls.

Implementing a `get_token()` helper function that intelligently checks the token's expiry and refreshes it only when necessary is the most efficient and robust approach. This avoids unnecessary token fetches while ensuring that API calls always use a valid token.

Why the other options are wrong

  • A. Fetching a new token for *every* command is inefficient, as the token might still be valid, leading to unnecessary API calls to the authentication endpoint.
  • B. Refreshing once daily is insufficient for a token with a 15-minute expiry, leading to expired tokens and failed API calls.
  • C. Manually updating the token is impractical and defeats the purpose of automation, especially with a short expiry time.

Automated Token Refresh (Integration)

For integrations using short-lived authentication tokens, an automated token refresh mechanism (e.g., a helper function) should be implemented to check token validity and refresh it before API calls.

  • Ensures API calls use valid tokens.
  • Checks expiry before refresh.
  • Avoids unnecessary authentication calls.

Memory trick: Keep your 'token' fresh, like a refreshing drink.

More Integrations questions