PSE-STRATA-PRO-24 · Question #58
Regarding APIs, a customer RFP states: "The vendor's firewall solution must provide an API with an enforcement mechanism to deactivate API keys after two hours." How should the response address this…
The correct answer is D. Yes - The default setting must be changed from no limit to 120 minutes. Palo Alto Networks' PAN-OS supports API keys for authentication when interacting with the firewall's RESTful and XML-based APIs. By default, API keys do not have an expiration time set, but the expiration time for API keys can be configured by an administrator to meet specific…
Question
Regarding APIs, a customer RFP states: "The vendor's firewall solution must provide an API with an enforcement mechanism to deactivate API keys after two hours." How should the response address this clause?
Options
- AYes - This is the default setting for API keys.
- BNo - The PAN-OS XML API does not support keys.
- CNo - The API keys can be made, but there is no method to deactivate them based on time.
- DYes - The default setting must be changed from no limit to 120 minutes.
How the community answered
(54 responses)- B2% (1)
- C4% (2)
- D94% (51)
Explanation
Palo Alto Networks' PAN-OS supports API keys for authentication when interacting with the firewall's RESTful and XML-based APIs. By default, API keys do not have an expiration time set, but the expiration time for API keys can be configured by an administrator to meet specific requirements, such as a time-based deactivation after two hours. This is particularly useful for compliance and security purposes, where API keys should not remain active indefinitely. Option D (Correct): The correct response to the RFP clause is that the default API key settings need to be modified to set the expiration time to 120 minutes (2 hours). This aligns with the customer requirement to enforce API key deactivation based on time. Administrators can configure this using the PAN-OS management interface or the CLI.
Topics
Community Discussion
No community discussion yet for this question.