Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy
A security analyst is configuring a new integration instance in Cortex XSOAR. The external service requires a specific header, `X-API-Key`, to be sent with every request for authentication. Where should the analyst configure this custom header within the integration instance settings to ensure it's included in all API calls made by this instance?
- AWithin the 'Description' field of the integration.
- BIn the 'Advanced' section, under 'Additional Headers'.
- CIn the 'Proxy Settings' section.
- DBy directly modifying the integration's Python code.
Show answer & explanationAnswer & explanation
Correct answer: B. In the 'Advanced' section, under 'Additional Headers'.
Custom HTTP headers, such as API keys or specific authentication tokens, are configured in the 'Advanced' section of an integration instance under 'Additional Headers' to be sent with all requests.
Why the other options are wrong
- A. The 'Description' field is for informational text and does not affect the integration's runtime behavior or send headers.
- C. Proxy settings deal with network routing, not custom HTTP headers for authentication.
- D. While possible for custom integrations, for out-of-the-box integrations, this is not the standard or recommended way to add instance-specific headers; using the UI is preferred.
Integration Custom Headers
Custom HTTP headers can be configured in integration instances to include specific authentication tokens or other required information in all API requests made by that instance.
- Configured per integration instance.
- Found in the 'Advanced' section of the instance settings.
- Useful for API keys, custom authentication, or specific content types.
Memory trick: Instances are configured to connect, so look for connection settings.