Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy

A security analyst is developing a custom integration that needs to retrieve a large volume of security events from a third-party SIEM. The SIEM's API implements cursor-based pagination, where each response includes a `next_cursor` field, and subsequent requests must include this cursor to fetch the next set of results. How should the integration handle this pagination efficiently to retrieve all events?

  1. AMake a single API call and assume all events are returned, ignoring any pagination indicators.
  2. BSet a fixed number of API calls (e.g., 10) to retrieve events, then stop.
  3. CImplement a `while` loop that continues to make API calls as long as a `next_cursor` is present in the response.
  4. DStore the `next_cursor` in Cortex XSOAR context and require manual execution of subsequent calls.
Show answer & explanation

Correct answer: C. Implement a `while` loop that continues to make API calls as long as a `next_cursor` is present in the response.

Cursor-based pagination requires making successive API calls, passing the `next_cursor` from the previous response to the next request. A `while` loop is the most appropriate and efficient programmatic structure to automate this repetitive fetching until all pages are retrieved.

Why the other options are wrong

  • A. Ignoring pagination will result in incomplete data retrieval, missing most events if the dataset is large.
  • B. A fixed number of calls is arbitrary and will likely result in incomplete data if the total number of pages exceeds this limit, or unnecessary calls if fewer pages exist.
  • D. Requiring manual execution defeats the purpose of automation and is highly inefficient for retrieving large datasets that span multiple pages.

Cursor-Based Pagination

A pagination method where an API returns a 'cursor' (an opaque string or ID) with each response, which must be included in the subsequent request to retrieve the next set of results.

  • Common for large datasets to maintain state.
  • Requires iterative requests until no cursor is returned.
  • Often implemented with a `while` loop in integration code.

Memory trick: Cursor keeps you going, loop until done.

More Integrations questions