Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security engineer is troubleshooting a custom integration where a specific command, `get-alert-details`, consistently fails with a `Connection refused` error, while other commands in the same integration instance work correctly. The integration uses a self-deployed engine. What is the MOST likely cause of this specific command failure?

  1. AThe external API server is down or unreachable only for the `get-alert-details` endpoint.
  2. BThe `get-alert-details` command has an incorrect API endpoint configured.
  3. CThe `get-alert-details` command's Python code has a syntax error.
  4. DThe self-deployed engine has insufficient network access to the `get-alert-details` API endpoint.
Show answer & explanation

Correct answer: D. The self-deployed engine has insufficient network access to the `get-alert-details` API endpoint.

If other commands in the *same integration instance* are working, it implies the general integration setup, API key, and basic connectivity for the engine are fine. A `Connection refused` error for a *specific command* strongly suggests that the self-deployed engine lacks network access (e.g., firewall rule, routing issue) to the *particular endpoint* that `get-alert-details` is trying to reach, while other endpoints are accessible.

Why the other options are wrong

  • A. While possible, it's less likely for an API server to be down for *only one specific endpoint* while others are up. More commonly, the entire server/service would be down, affecting all commands.
  • B. An incorrect API endpoint would likely result in a 404 or similar HTTP error, not `Connection refused`.
  • C. A syntax error would prevent the command from even starting or result in a Python traceback, not a `Connection refused` network error.

Specific Endpoint Network Access

When a specific command in a Cortex XSOAR custom integration consistently fails with `Connection refused`, while other commands work, it often indicates a network access issue (e.g., firewall, routing) preventing the self-deployed engine from reaching that particular API endpoint.

  • Other commands in same instance work.
  • Error is `Connection refused` (network-level).
  • Suggests endpoint-specific network blockage.

Memory trick: If *one* 'door' is 'refused', check *that door's* path.

More Integrations questions