PCNSA App-ID and Content-ID Practice Question
A company wants to block file uploads of PDFs to the internet via HTTP. Which Content-ID profile should be configured?
⚠ Common exam trap
A common mix-up: candidates confuse File Blocking with URL Filtering or Antivirus, assuming that blocking a file type is handled by URL categories or malware scanning, when in fact it requires a dedicated Content-ID profile that inspects the file itself regardless of the URL or threat status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File Blocking Profile
The File Blocking Profile is specifically designed to block file transfers based on file type, such as PDF, over protocols like HTTP. This profile uses Content-ID to inspect the file content and enforce blocking policies for uploads or downloads, making it the appropriate choice to prevent PDF uploads to the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vulnerability Protection Profile
Why it's wrong here
Vulnerability Protection detects exploits and attacks against hosts, not file types being uploaded. It tempts because it inspects HTTP traffic, and would be correct for blocking attempts to exploit a known vulnerability in a web application rather than stopping a PDF being posted outbound.
- ✗
URL Filtering Profile
Why it's wrong here
URL Filtering matches request destinations and categories, not file contents, so it cannot inspect an HTTP body for PDF payloads. It is tempting because it governs web traffic, and would be correct for blocking access to known malicious or unwanted sites rather than preventing document uploads.
- ✓
File Blocking Profile
Why this is correct
A File Blocking Profile inspects HTTP traffic and blocks transfers by file type, matching the PDF requirement directly. Unlike Data Filtering, which targets sensitive content patterns, or URL Filtering, which governs destinations, it enforces the stem's constraint: preventing outbound uploads of a specified file extension to the internet.
- ✗
Virus Profile
Why it's wrong here
The Virus profile scans for malware signatures, so a benign PDF upload passes it. It is tempting because it examines file content, and would be correct for blocking transfers of files matching known malicious signatures rather than enforcing a file-type upload restriction.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.