Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security engineer is developing a custom integration that needs to interact with an external API. This API requires client certificate authentication (mTLS) for all connections. When configuring the integration instance in Cortex XSOAR, which two parameters are essential for enabling successful mTLS communication?
- AAPI Key and API URL.
- BProxy Address and Proxy Port.
- CClient Certificate and Client Key.
- DUsername and Password.
Show answer & explanationAnswer & explanation
Correct answer: C. Client Certificate and Client Key.
For client certificate authentication (mTLS), the integration needs both the client's public certificate and its corresponding private key. These are typically provided in the integration instance configuration to establish a secure, mutually authenticated connection.
Why the other options are wrong
- A. API Key and API URL are for basic API authentication and endpoint definition, not mTLS.
- B. Proxy Address and Proxy Port are for routing network traffic through a proxy, unrelated to mTLS authentication itself.
- D. Username and Password are for basic authentication, not certificate-based mTLS.
mTLS Client Configuration
Client certificate authentication (mTLS) in Cortex XSOAR integrations requires configuring both the client's public certificate and its private key.
- Ensures mutual authentication.
- Requires client certificate and private key.
- Common in highly secure environments.
Memory trick: mTLS needs 'two keys' to shake hands.