PCNSA App-ID and Content-ID Practice Question
A security administrator at a healthcare company needs to detect and block outbound emails that contain patient Social Security numbers. The company uses Microsoft Exchange over SMTP, and the firewall is running PAN-OS 10.1 with the appropriate subscriptions. Which Content-ID feature should the administrator configure to inspect the email body and attachments for sensitive data patterns?
⚠ Common exam trap
Many candidates confuse data loss prevention with file type control, assuming that blocking certain file types or scanning for malware will also detect sensitive data patterns in email content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Filtering profile
Data Filtering profiles are designed to detect and control sensitive information such as credit card numbers, Social Security numbers, and custom patterns within allowed traffic. When applied to a security rule that permits SMTP, the firewall inspects the email body and attachments for these patterns and can block or alert. This is the correct Content-ID feature for preventing outbound emails with patient SSNs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Filtering profile
Why this is correct
Data Filtering profiles use predefined or custom data patterns to detect sensitive information such as Social Security numbers within allowed traffic. Applied to a security rule, the profile inspects the payload of email protocols like SMTP and can alert, block, or log when patterns match. This directly addresses the requirement to prevent outbound emails containing patient SSNs.
- ✗
Antivirus security profile
Why it's wrong here
Antivirus profiles scan for malicious code in files and protocols, not for sensitive data patterns. They would not detect a Social Security number in an email body or a benign attachment. Using an Antivirus profile here would not meet the requirement to block outbound emails containing patient SSNs, making it the wrong choice.
- ✗
File Blocking profile
Why it's wrong here
File Blocking profiles control the transfer of files based on file type, direction, and application. They do not inspect file contents for data patterns such as Social Security numbers. While they could block an entire attachment type, they cannot selectively detect and block emails that contain sensitive data within the body or attachments, so they fail this scenario.
- ✗
URL Filtering profile
Why it's wrong here
URL Filtering profiles categorize and control web traffic based on URLs, not email content. They cannot inspect SMTP traffic for data patterns like Social Security numbers. While URL Filtering is a Content-ID feature, it is irrelevant to detecting sensitive data in outbound email, so it does not satisfy the scenario's requirement.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.