Courseiva
App-ID and Content-ID →mediumMultiple Choice

PCNSA App-ID and Content-ID Practice Question

A security administrator at a healthcare company needs to detect and block outbound emails that contain patient Social Security numbers. The company uses Microsoft Exchange over SMTP, and the firewall is running PAN-OS 10.1 with the appropriate subscriptions. Which Content-ID feature should the administrator configure to inspect the email body and attachments for sensitive data patterns?

⚠ Common exam trap

Many candidates confuse data loss prevention with file type control, assuming that blocking certain file types or scanning for malware will also detect sensitive data patterns in email content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Filtering profile

Data Filtering profiles are designed to detect and control sensitive information such as credit card numbers, Social Security numbers, and custom patterns within allowed traffic. When applied to a security rule that permits SMTP, the firewall inspects the email body and attachments for these patterns and can block or alert. This is the correct Content-ID feature for preventing outbound emails with patient SSNs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data Filtering profile

    Why this is correct

    Data Filtering profiles use predefined or custom data patterns to detect sensitive information such as Social Security numbers within allowed traffic. Applied to a security rule, the profile inspects the payload of email protocols like SMTP and can alert, block, or log when patterns match. This directly addresses the requirement to prevent outbound emails containing patient SSNs.

  • ✗

    Antivirus security profile

    Why it's wrong here

    Antivirus profiles scan for malicious code in files and protocols, not for sensitive data patterns. They would not detect a Social Security number in an email body or a benign attachment. Using an Antivirus profile here would not meet the requirement to block outbound emails containing patient SSNs, making it the wrong choice.

  • ✗

    File Blocking profile

    Why it's wrong here

    File Blocking profiles control the transfer of files based on file type, direction, and application. They do not inspect file contents for data patterns such as Social Security numbers. While they could block an entire attachment type, they cannot selectively detect and block emails that contain sensitive data within the body or attachments, so they fail this scenario.

  • ✗

    URL Filtering profile

    Why it's wrong here

    URL Filtering profiles categorize and control web traffic based on URLs, not email content. They cannot inspect SMTP traffic for data patterns like Social Security numbers. While URL Filtering is a Content-ID feature, it is irrelevant to detecting sensitive data in outbound email, so it does not satisfy the scenario's requirement.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.