PCNSA App-ID and Content-ID Practice Question
A security administrator is configuring a Data Filtering profile to prevent sensitive customer data from leaving the network via webmail. The administrator wants to block any email that contains a U.S. Social Security Number. Which Data Filtering profile setting should be used to detect the SSN pattern?
⚠ Common exam trap
The trap here is assuming that a custom regex is needed for SSN detection, but Palo Alto Networks provides predefined patterns for common data types, simplifying configuration and improving accuracy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Predefined pattern for Social Security Number
The Data Filtering profile provides predefined patterns for common sensitive data types, including U.S. Social Security Numbers. By selecting the predefined SSN pattern, the administrator can reliably detect and block emails containing SSNs. This leverages built-in regular expressions optimized for accurate detection, avoiding the need for custom patterns that may be error-prone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application override for webmail
Why it's wrong here
Application override changes the application identification for specific traffic, but it does not inspect content for sensitive data. It is used to force a custom application or bypass App-ID. This setting does not help in detecting SSNs; it is unrelated to Data Filtering content inspection.
- ✗
File type matching for .txt files
Why it's wrong here
File type matching detects files based on their type, not their content. It cannot identify SSNs within the file. Data Filtering requires content inspection using patterns, not file type. Therefore, this setting would not block emails containing SSNs unless the SSN is in a specific file type, which is not the requirement.
- ✓
Predefined pattern for Social Security Number
Why this is correct
The Data Filtering profile includes predefined patterns for common sensitive data types, such as U.S. Social Security Numbers. Selecting this pattern enables the firewall to detect and block traffic containing SSNs. This is the correct approach because it uses built-in regex patterns designed to match the SSN format, ensuring accurate detection without custom configuration.
- ✗
Custom pattern using a regular expression
Why it's wrong here
While a custom pattern could be created to match SSNs, it is not necessary because a predefined pattern exists. Using a custom pattern might lead to false positives or negatives if not carefully crafted. The predefined pattern is optimized and tested for SSN detection, making it the better choice for this scenario.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.