Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A SOC team is deploying a new custom integration that connects to an internal REST API. During testing, they observe that commands executed via the integration occasionally fail with a timeout error, even though the API responds successfully within a few seconds when tested directly. The integration code uses standard Python requests library calls. What is the MOST likely cause of this issue?
- AThe default timeout configured for the custom integration commands is too low.
- BThe internal REST API is experiencing a high volume of requests from other services.
- CThe custom integration is missing a required input parameter for the API call.
- DThe Cortex XSOAR engine's network connectivity to the internal API is intermittent.
Show answer & explanationAnswer & explanation
Correct answer: A. The default timeout configured for the custom integration commands is too low.
Cortex XSOAR commands, especially for custom integrations, have a default timeout. If the external API's response time, even if generally quick, occasionally exceeds this default, it will result in a timeout error within Cortex XSOAR, even if the API eventually processes the request.
Why the other options are wrong
- B. High volume on the API side would likely cause the API itself to return errors (e.g., 429 Too Many Requests) or experience its own timeouts, not necessarily a timeout within XSOAR if the API eventually responds.
- C. A missing parameter would likely lead to an API error response (e.g., 400 Bad Request), not a timeout.
- D. Intermittent network connectivity would typically manifest as connection errors or full failures, not specifically timeouts after a partial wait.
Integration Command Timeout
The maximum duration Cortex XSOAR waits for a response from an external service after executing an integration command before unilaterally terminating the operation.
- Default timeouts exist for integration commands.
- Can be configured for specific commands or integration instances.
- Exceeding this timeout results in a 'timeout' error in XSOAR.
Memory trick: Command issues often stem from timeouts or bad connections.