Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard
A security engineer is developing a custom integration for Cortex XSOAR. The integration needs to interact with an external API that requires a unique, session-based token for each API call, which is obtained by a separate authentication endpoint. The token has a short expiry (5 minutes) and must be refreshed frequently. Which feature of the DemistoIntegration class is MOST suitable for managing and automatically refreshing this type of token?
- AImplementing a `get_token` method and utilizing the `self.session` object's token management.
- BEmbedding the token directly into the API endpoint URL for every request.
- CUsing a global variable to store the token and manually refreshing it in each command.
- DStoring the token as an integration parameter and setting a high fetch interval.
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing a `get_token` method and utilizing the `self.session` object's token management.
The `DemistoIntegration` class provides mechanisms, often through the `self.session` object (or similar client objects), for managing authentication tokens. By implementing a `get_token` method, the integration can encapsulate the token acquisition and refresh logic, ensuring tokens are automatically renewed before each use, which is ideal for short-lived, session-based tokens.
Why the other options are wrong
- B. Embedding tokens in URLs is highly insecure as it exposes sensitive information in logs and is not a mechanism for management or refresh.
- C. Global variables are not secure or efficient for token management, and manual refresh in each command is cumbersome and error-prone.
- D. Storing the token as an integration parameter doesn't inherently manage its refresh, and a high fetch interval is irrelevant to token expiry.
Integration Token Management
The process within a Cortex XSOAR custom integration to acquire, store, refresh, and apply authentication tokens required for interacting with external APIs.
- Best handled within the `DemistoIntegration` class or its `BaseClient`.
- Often involves a `get_token` method for on-demand refresh.
- Crucial for APIs with short-lived or session-based tokens.
Memory trick: Tokens need dynamic refresh, use the session's power.