Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy
A security engineer is configuring a new integration instance in Cortex XSOAR. The external service requires a specific API key that is unique to each user and must be rotated every 90 days. Which of the following is the MOST secure and efficient method to manage this credential within Cortex XSOAR for the integration?
- AEmbed the API key in a playbook task that passes it to the integration.
- BSave the API key as a plaintext global variable accessible by all users.
- CStore the API key as an encrypted integration parameter with a rotation policy.
- DHardcode the API key directly into the integration's Python script.
Show answer & explanationAnswer & explanation
Correct answer: C. Store the API key as an encrypted integration parameter with a rotation policy.
Storing credentials as encrypted integration parameters is the standard and most secure method in Cortex XSOAR. It allows for secure storage, access control, and facilitates rotation policies, aligning with security best practices.
Why the other options are wrong
- A. Passing credentials via playbook tasks can expose them in logs or task details, and does not centralize management or rotation.
- B. Storing credentials in plaintext is highly insecure and grants unauthorized access, violating fundamental security principles.
- D. Hardcoding credentials is a severe security risk as it exposes sensitive information and makes rotation difficult.
Secure Credential Management
The practice of securely storing, accessing, and rotating sensitive authentication information (like API keys, passwords) within an integration platform.
- Cortex XSOAR uses encrypted integration parameters for secure storage.
- Supports rotation policies for automated credential updates.
- Prevents exposure of sensitive data in scripts or logs.
Memory trick: Secure keys rotate, don't expose or hardcode.