Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security architect is designing a new integration for Cortex XSOAR that requires secure access to a cloud service using short-lived credentials, which are regularly rotated. This service explicitly supports OpenID Connect (OIDC) for authentication. The architect wants to leverage XSOAR's native capabilities to manage and refresh these credentials automatically. Which type of integration configuration is best suited for this requirement?
- AOAuth 2.0 / OIDC based authentication flow.
- BStatic certificate-based authentication.
- CBasic Authentication (username/password)
- DAPI Key authentication with manual rotation.
Show answer & explanationAnswer & explanation
Correct answer: A. OAuth 2.0 / OIDC based authentication flow.
OAuth 2.0 and OIDC are designed for delegated authorization and token-based authentication, supporting short-lived tokens and automatic refresh mechanisms. Cortex XSOAR provides native support for these flows, making them ideal for securely integrating with services that require dynamic, rotated credentials without manual intervention.
Why the other options are wrong
- B. Static certificates are typically long-lived and do not provide the dynamic, short-lived credential management required.
- C. Basic authentication does not support short-lived, automatically rotated credentials.
- D. API keys are generally static or require manual rotation, which contradicts the requirement for automatic rotation of short-lived credentials.
OAuth 2.0 / OIDC for Integrations
A framework used for delegated authorization and authentication, enabling secure access with short-lived, automatically refreshable tokens.
- Supports various 'flows' (e.g., Client Credentials, Authorization Code).
- Ideal for integrating with cloud services requiring dynamic credentials.
- Cortex XSOAR can manage token refresh automatically.
Memory trick: OAuth makes credentials flow, refreshing as they go.