Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security engineer is developing a custom integration that needs to interact with an external API that is protected by client certificate authentication (mutual TLS). The engineer has obtained the client certificate, its corresponding private key, and the CA certificate chain. Which specific fields in the Cortex XSOAR integration configuration template (YAML file) must be defined to allow the integration to securely present these certificates during API calls?

  1. A`username` and `password`
  2. B`certificate` and `private_key`
  3. C`api_key` and `api_url`
  4. D`proxy_username` and `proxy_password`
Show answer & explanation

Correct answer: B. `certificate` and `private_key`

For client certificate authentication (mutual TLS), the integration needs to present its own certificate and private key to the server. Cortex XSOAR integration configuration templates provide specific fields, typically `certificate` and `private_key`, to store and use these credentials for secure API communication.

Why the other options are wrong

  • A. These are for basic authentication, not mutual TLS.
  • C. These are for API key-based authentication, not mutual TLS.
  • D. These are for proxy authentication, not direct API authentication via mutual TLS.

Client Certificate Authentication (mTLS)

A security mechanism where both the client (integration) and server authenticate each other using digital certificates during the TLS handshake.

  • Requires the client's certificate and private key.
  • Often used in highly secure environments.
  • XSOAR integrations can be configured with these credentials.

Memory trick: Cert and Key: the secure pair for client identity.

More Integrations questions