Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
An incident responder is reviewing an integration's configuration within Cortex XSOAR. The integration is set to `Fetch incidents` every 5 minutes. The responder observes that sometimes incidents are not immediately processed, even if they appear in the external system. After inspecting the 'Last Run' field, it is noted that the integration might occasionally take longer than 5 minutes to complete a fetch operation. What is the primary implication of a fetch interval being shorter than the actual fetch duration?
- AIncidents will be duplicated in Cortex XSOAR.
- BThe 'Last Run' field will not update correctly.
- CThe integration will consume excessive CPU resources on the XSOAR engine.
- DNew fetch cycles might be skipped or delayed, leading to incident processing delays.
Show answer & explanationAnswer & explanation
Correct answer: D. New fetch cycles might be skipped or delayed, leading to incident processing delays.
If a fetch interval is shorter than the actual fetch duration, the integration might miss or delay subsequent fetch cycles because the previous one is still running. This can lead to incidents not being processed in a timely manner or even being skipped if the platform has logic to prevent concurrent fetch operations for the same instance.
Why the other options are wrong
- A. Duplication is less likely unless the external system consistently returns already fetched incidents or the integration's `last_run` logic is flawed. The primary issue is delayed processing.
- B. The 'Last Run' field typically updates upon completion of a fetch, so it would update, but it might reflect a longer interval than configured.
- C. While a long-running fetch consumes resources, the core issue of a *shorter interval than duration* is about scheduling and data timeliness, not necessarily excessive CPU consumption (unless the fetch is inefficient).
Integration Fetch Interval vs. Duration
The fetch interval for an integration should be greater than or equal to its typical fetch duration to prevent skipped or delayed incident processing cycles.
- Interval defines frequency.
- Duration is actual execution time.
- Interval < Duration causes delays/skips.
Memory trick: Intervals must be longer than the 'fetch' operation itself.