Exam SecOps-Pro Topic 1 Question 63 Discussion
Actual exam question for Palo Alto Networks's SecOps-Pro exam
Question #: 63
Topic #: 1
Question #: 63
Topic #: 1
Consider a scenario where an XSOAR playbook needs to dynamically query a vulnerability management system (VMS) for asset vulnerabilities and then update a CMDB with remediation status. The VMS has a REST API that requires OAuth 2.0 client credentials grant type for authentication, and the CMDB uses a SOAP API. How would an XSOAR developer architect the integration to handle these authentication and communication complexities within a single playbook task?
Suggested Answer: B Vote an answer
This scenario requires handling distinct authentication (OAuth 2.0) and communication protocols (REST, SOAP). Option B directly addresses this by recommending custom Python integrations. For OAuth 2.0, requests_oauthlib is a standard library. For SOAP, suds-py3 (or similar) is appropriate. These custom integrations provide the necessary flexibility and control over authentication flows and API interactions, which are then exposed as commands to the playbook. Option C is incomplete as XSOAR's generic integrations may not fully handle complex OAuth 2.0 flows without custom code. Option A is insecure and not idiomatic for XSOAR. Options D and E are either too manual or assume out-of-the-box support that might not exist for specific VMS/CMDB versions or their authentication requirements.
by Marguerite at Oct 08, 2026, 02:42 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).