Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A cybersecurity firm is developing a custom integration for Cortex XSOAR to interact with a proprietary vulnerability management system. The integration needs to perform actions such as fetching vulnerability reports, updating ticket statuses, and creating new vulnerability records. The firm's developers are using Python to write the integration code. Which Python class must their custom integration script extend to ensure compatibility and proper functioning within the XSOAR framework?

  1. AScriptClass
  2. BIntegrationBase
  3. CDemistoIntegration
  4. DBaseIntegration
Show answer & explanation

Correct answer: C. DemistoIntegration

In Cortex XSOAR, custom Python integrations must extend the `DemistoIntegration` class (or its specialized subclasses like `BaseClient`) to inherit the necessary methods and structure for interacting with the XSOAR platform. This ensures proper command execution, parameter handling, and output formatting.

Why the other options are wrong

  • A. `ScriptClass` is not a standard XSOAR base class for integrations.
  • B. `IntegrationBase` is not the correct class name in XSOAR for Python integrations.
  • D. `BaseIntegration` is not the correct class name in XSOAR for Python integrations.

DemistoIntegration Class

The base Python class in Cortex XSOAR that all custom integrations must extend to interact with the platform.

  • Provides core methods for command execution and parameter handling.
  • Ensures compatibility with XSOAR's integration framework.
  • Derived from `BaseClient` for API interactions or directly for simpler cases.

Memory trick: DemistoIntegration is the foundation for all custom Python scripts.

More Integrations questions