Courseiva
App-ID and Content-ID →hardMultiple Choice

PCNSA App-ID and Content-ID Practice Question

A security administrator is configuring a Data Filtering profile to prevent sensitive customer data from leaving the network via webmail. The administrator wants to block any email that contains a U.S. Social Security Number. Which Data Filtering profile setting should be used to detect the SSN pattern?

⚠ Common exam trap

The trap here is assuming that a custom regex is needed for SSN detection, but Palo Alto Networks provides predefined patterns for common data types, simplifying configuration and improving accuracy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Predefined pattern for Social Security Number

The Data Filtering profile provides predefined patterns for common sensitive data types, including U.S. Social Security Numbers. By selecting the predefined SSN pattern, the administrator can reliably detect and block emails containing SSNs. This leverages built-in regular expressions optimized for accurate detection, avoiding the need for custom patterns that may be error-prone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application override for webmail

    Why it's wrong here

    Application override changes the application identification for specific traffic, but it does not inspect content for sensitive data. It is used to force a custom application or bypass App-ID. This setting does not help in detecting SSNs; it is unrelated to Data Filtering content inspection.

  • ✗

    File type matching for .txt files

    Why it's wrong here

    File type matching detects files based on their type, not their content. It cannot identify SSNs within the file. Data Filtering requires content inspection using patterns, not file type. Therefore, this setting would not block emails containing SSNs unless the SSN is in a specific file type, which is not the requirement.

  • ✓

    Predefined pattern for Social Security Number

    Why this is correct

    The Data Filtering profile includes predefined patterns for common sensitive data types, such as U.S. Social Security Numbers. Selecting this pattern enables the firewall to detect and block traffic containing SSNs. This is the correct approach because it uses built-in regex patterns designed to match the SSN format, ensuring accurate detection without custom configuration.

  • ✗

    Custom pattern using a regular expression

    Why it's wrong here

    While a custom pattern could be created to match SSNs, it is not necessary because a predefined pattern exists. Using a custom pattern might lead to false positives or negatives if not carefully crafted. The predefined pattern is optimized and tested for SSN detection, making it the better choice for this scenario.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.