Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security engineer is developing a custom integration for Cortex XSOAR. The integration needs to interact with an external API that requires a unique, session-based token for each API call, which is obtained by a separate authentication endpoint. The token has a short expiry (5 minutes) and must be refreshed frequently. Which feature of the DemistoIntegration class is MOST suitable for managing and automatically refreshing this type of token?

  1. AImplementing a `get_token` method and utilizing the `self.session` object's token management.
  2. BEmbedding the token directly into the API endpoint URL for every request.
  3. CUsing a global variable to store the token and manually refreshing it in each command.
  4. DStoring the token as an integration parameter and setting a high fetch interval.
Show answer & explanation

Correct answer: A. Implementing a `get_token` method and utilizing the `self.session` object's token management.

The `DemistoIntegration` class provides mechanisms, often through the `self.session` object (or similar client objects), for managing authentication tokens. By implementing a `get_token` method, the integration can encapsulate the token acquisition and refresh logic, ensuring tokens are automatically renewed before each use, which is ideal for short-lived, session-based tokens.

Why the other options are wrong

  • B. Embedding tokens in URLs is highly insecure as it exposes sensitive information in logs and is not a mechanism for management or refresh.
  • C. Global variables are not secure or efficient for token management, and manual refresh in each command is cumbersome and error-prone.
  • D. Storing the token as an integration parameter doesn't inherently manage its refresh, and a high fetch interval is irrelevant to token expiry.

Integration Token Management

The process within a Cortex XSOAR custom integration to acquire, store, refresh, and apply authentication tokens required for interacting with external APIs.

  • Best handled within the `DemistoIntegration` class or its `BaseClient`.
  • Often involves a `get_token` method for on-demand refresh.
  • Crucial for APIs with short-lived or session-based tokens.

Memory trick: Tokens need dynamic refresh, use the session's power.

More Integrations questions