Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy
A security architect is designing a custom integration for Cortex XSOAR that needs to interact with an internal, highly sensitive API. This API uses mutual TLS (mTLS) for authentication, requiring both the client (Cortex XSOAR engine) and the server to present and validate certificates. Which two parameters are essential to configure within the integration instance to establish a successful mTLS connection?
- AProxy Host and Proxy Port
- BClient Certificate (PEM) and Client Key (PEM)
- CAPI Key and API URL
- DUsername and Password
Show answer & explanationAnswer & explanation
Correct answer: B. Client Certificate (PEM) and Client Key (PEM)
Mutual TLS requires both the client and the server to present and validate certificates. For the client (Cortex XSOAR) to authenticate to the server, it must provide its client certificate and the corresponding private key. These are typically provided in PEM format.
Why the other options are wrong
- A. Proxy settings are for network routing, not direct authentication via mTLS.
- C. API Key and API URL are common for many integrations but not specific to mTLS.
- D. Username and Password are for basic authentication or token generation, not mTLS.
Mutual TLS (mTLS) Client Configuration
For a Cortex XSOAR integration to establish a mutual TLS (mTLS) connection, it must be configured with the client's X.509 certificate and its corresponding private key, typically in PEM format, to authenticate itself to the server.
- Both client and server authenticate each other.
- Requires client certificate and private key.
- Commonly used for highly sensitive internal APIs.
Memory trick: Mutual trust needs two 'keys' – one for the lock, one to prove who you are.