PCNSA Policy Evaluation and Management Practice Question
A company wants to block file-sharing applications like BitTorrent, but allow HTTP and HTTPS. Which type of policy is most appropriate to achieve this granular control?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policy with application-ID.
Application-ID allows granular control over applications, not just ports. Option B is a decryption policy and does not control application access. Option C is a security policy with service only, which restricts based on port/protocol, not application. Option D is policy-based forwarding, used for path selection, not for blocking applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security policy with application-ID.
Why this is correct
A Security policy with application-ID identifies BitTorrent by its application signatures regardless of port or protocol, then blocks it, while separate rules permit HTTP and HTTPS. Port-based rules alone cannot distinguish file-sharing traffic from web traffic.
- ✗
Decryption policy.
Why it's wrong here
Decryption policy governs which sessions are decrypted for inspection; it neither permits nor denies applications. It is tempting because inspecting encrypted BitTorrent traffic appears necessary, but decryption only exposes content to a security policy, which must then perform the actual App-ID block.
- ✗
Security policy with service only.
Why it's wrong here
A security policy matching only service ports cannot distinguish BitTorrent from HTTP or HTTPS, since file-sharing commonly tunnels over those same ports. It is tempting because service objects are the familiar way to permit web traffic, but granular blocking needs App-ID or application filters in the rule.
- ✗
Policy-based forwarding.
Why it's wrong here
Policy-based forwarding redirects matching traffic to a specified egress interface or next hop; it does not identify or block applications. It is tempting when traffic must exit via a particular ISP or tunnel, but App-ID enforcement requires a security policy rule with an application or application filter.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.