Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A SOC team is deploying a new custom integration that connects to an internal REST API. During testing, they observe that commands executed via the integration occasionally fail with a timeout error, even though the API responds successfully within a few seconds when tested directly. The integration code uses standard Python requests library calls. What is the MOST likely cause of this issue?

  1. AThe default timeout configured for the custom integration commands is too low.
  2. BThe internal REST API is experiencing a high volume of requests from other services.
  3. CThe custom integration is missing a required input parameter for the API call.
  4. DThe Cortex XSOAR engine's network connectivity to the internal API is intermittent.
Show answer & explanation

Correct answer: A. The default timeout configured for the custom integration commands is too low.

Cortex XSOAR commands, especially for custom integrations, have a default timeout. If the external API's response time, even if generally quick, occasionally exceeds this default, it will result in a timeout error within Cortex XSOAR, even if the API eventually processes the request.

Why the other options are wrong

  • B. High volume on the API side would likely cause the API itself to return errors (e.g., 429 Too Many Requests) or experience its own timeouts, not necessarily a timeout within XSOAR if the API eventually responds.
  • C. A missing parameter would likely lead to an API error response (e.g., 400 Bad Request), not a timeout.
  • D. Intermittent network connectivity would typically manifest as connection errors or full failures, not specifically timeouts after a partial wait.

Integration Command Timeout

The maximum duration Cortex XSOAR waits for a response from an external service after executing an integration command before unilaterally terminating the operation.

  • Default timeouts exist for integration commands.
  • Can be configured for specific commands or integration instances.
  • Exceeding this timeout results in a 'timeout' error in XSOAR.

Memory trick: Command issues often stem from timeouts or bad connections.

More Integrations questions