Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A cybersecurity firm is developing a custom integration for Cortex XSOAR to interact with a partner's security appliance. The partner's API uses a unique challenge-response authentication mechanism where the integration must first request a challenge string, sign it with a pre-shared secret, and then send the signed challenge along with the original request. How should this custom authentication flow be implemented in the integration's Python code?

  1. ABy defining a separate utility function that generates the signed challenge for each command.
  2. BBy using the `demisto.credentials()` function to retrieve the challenge string.
  3. CBy extending the `BaseClient` class and overriding its `_http_request` method.
  4. DBy storing the pre-shared secret in `demisto.params()` and manually adding it to each request.
Show answer & explanation

Correct answer: C. By extending the `BaseClient` class and overriding its `_http_request` method.

Overriding the `_http_request` method of the `BaseClient` class is the most robust way to implement complex, custom authentication flows. This allows the integration to intercept every outgoing request, perform the challenge-response logic (get challenge, sign, add to headers/body), and then send the modified request, ensuring the custom authentication is applied consistently across all API calls.

Why the other options are wrong

  • A. While a utility function can generate the challenge, it still needs to be explicitly called and integrated into each command, leading to code duplication. Overriding `_http_request` is more elegant and centralized.
  • B. `demisto.credentials()` is for retrieving standard credentials, not for generating challenge strings or managing custom authentication logic.
  • D. Storing the secret in `demisto.params()` is fine, but manually adding it to each request does not implement the challenge-response *flow* automatically.

Overriding `_http_request` for Custom Auth

Extending the `BaseClient` class in a custom integration and overriding its `_http_request` method to implement complex, non-standard authentication mechanisms (e.g., challenge-response, custom signing) that must be applied to every outgoing API call.

  • Centralizes custom authentication logic.
  • Ensures all requests are properly authenticated.
  • Provides a hook to modify requests before sending.

Memory trick: Override the request to truly own the auth process.

More Integrations questions