Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy

A security analyst is configuring a new integration in Cortex XSOAR to fetch incidents from a third-party SIEM. During the initial setup, the analyst needs to ensure that the connection to the SIEM API is secure and authorized. Which credential type should the analyst prioritize for this integration to establish a secure and programmatic connection?

  1. AUsername and password
  2. BAPI Key
  3. COAuth 2.0 Client Credentials
  4. DSSH Key
Show answer & explanation

Correct answer: B. API Key

For programmatic access to a third-party SIEM API, an API Key is generally the most straightforward and common method for authentication, providing a secure and easily manageable credential type. While other methods exist, API keys are designed for this exact purpose.

Why the other options are wrong

  • A. Username and password can be used but are less secure and harder to manage for programmatic access compared to API keys.
  • C. OAuth 2.0 Client Credentials are used for machine-to-machine authentication but are often more complex to set up than a simple API key for basic integration.
  • D. SSH Keys are primarily used for secure shell access to servers, not typically for authenticating to RESTful APIs.

API Key

A unique identifier used to authenticate a user, developer, or calling program to an API.

  • Provides access control to an API.
  • Often a long string of alphanumeric characters.
  • Should be kept confidential to prevent unauthorized access.

Memory trick: API Keys unlock web services for automated tasks.

More Integrations questions