PCNSA App-ID and Content-ID Practice Question
A company uses App-ID to control cloud storage applications. Users report that uploads to Google Drive are blocked even though a rule allows 'google-drive-base'. What is the most likely cause?
⚠ Common exam trap
Test-takers frequently assume a single application signature like 'google-drive-base' covers all traffic for that application, but Palo Alto Networks App-ID often splits applications into multiple sub-application signatures for granular control, and failing to allow the specific sub-application for uploads will result in blocked traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule allows only 'google-drive-base' but the uploads use 'google-drive-upload'.
App-ID uses multiple application signatures to identify different functions within an application. 'google-drive-base' covers basic Google Drive traffic, but uploads are typically identified by a separate application signature, 'google-drive-upload'. Since the rule only allows 'google-drive-base', the firewall blocks the upload traffic because it does not match the permitted application. This is a common scenario where granular App-ID signatures must be explicitly allowed for specific actions like uploads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall is not connected to the cloud for App-ID updates.
Why it's wrong here
App-ID updates are pulled from Palo Alto Networks update servers, not a cloud connection, so this cannot explain the block. It is tempting because App-ID signatures do require periodic updates, and stale signatures would be the correct diagnosis if the application itself were unrecognised rather than a sub-application mismatch.
- ✓
The rule allows only 'google-drive-base' but the uploads use 'google-drive-upload'.
Why this is correct
Google Drive uploads traverse a distinct App-ID signature, 'google-drive-upload', separate from 'google-drive-base'. Since the security rule permits only the base application, the upload session matches no allow rule and is denied by the implicit interzone default. App-ID identifies each function independently, so both signatures must be permitted for full access.
- ✗
Decryption is not enabled for Google Drive traffic.
Why it's wrong here
Without decryption, the firewall cannot inspect the TLS-encrypted upload session, so App-ID may identify the application but not the file-transfer function, and the base rule's action does not permit the upload. It is tempting because decryption is required for encrypted traffic, and would be correct where policy depends on inspecting HTTPS content.
- ✗
An application override is configured for Google Drive.
Why it's wrong here
An application override forces Google Drive traffic onto a custom application or port, bypassing the App-ID signature that the google-drive-base rule matches, so the allow rule never applies. It is tempting because overrides exist to handle custom or non-standard applications, and would be correct for an internally hosted app App-ID misclassifies.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.