Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksHard
A security analyst is building a playbook that needs to interact with a custom internal REST API. This API requires an authentication token that is valid for 15 minutes and must be obtained from an OAuth server before any API calls are made. The playbook might run for longer than 15 minutes or make multiple calls over an extended period. To ensure API calls do not fail due to an expired token, how should the playbook manage the authentication token?
- AObtain a new token before each API call, or when an API call fails with an authentication error.
- BObtain the token once at the beginning of the playbook and store it in a global variable.
- CEmbed the token directly into the integration configuration for the custom API.
- DStore the token in the incident context and set a timer to refresh it every 10 minutes.
Show answer & explanationAnswer & explanation
Correct answer: A. Obtain a new token before each API call, or when an API call fails with an authentication error.
Obtaining a new token before each call, or specifically on authentication failure, is the most robust way to handle short-lived tokens in a playbook that might run for extended periods or make intermittent calls, ensuring the token is always fresh when needed.
Why the other options are wrong
- B. A global variable doesn't address the 15-minute expiration if the playbook runs longer.
- C. Embedding a short-lived token in integration configuration is not practical as it requires manual updates and cannot be dynamically refreshed by the playbook.
- D. Setting a timer in a playbook is not a native feature for context data; this would require complex custom scripting and might not align with variable playbook execution times.
Dynamic Token Management
The practice of acquiring and refreshing API authentication tokens within a playbook's execution flow to ensure valid credentials for external API interactions, especially for short-lived tokens.
- Crucial for APIs with expiring tokens (e.g., OAuth).
- Can involve pre-call token acquisition or on-failure refresh logic.
- Avoids hardcoding and manual updates for dynamic credentials.
Memory trick: Always check your key; if it's old, get a new one before opening the door.