Courseiva
App-ID and Content-ID →hardMultiple Select

PCNSA App-ID and Content-ID Practice Question

A security administrator is configuring a Data Filtering profile to prevent sensitive information from leaving the corporate network via web traffic. The administrator wants to detect and block patterns such as credit card numbers and social security numbers in HTTP POST requests. Which two actions can the Data Filtering profile take when a match is found? (Choose two.)

⚠ Common exam trap

The trap here is assuming that Data Filtering profiles have the same actions as other security profiles, such as 'Reset Client' or 'Allow', when in fact they only support Alert and Block.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alert

Data Filtering profiles support two primary actions when a pattern match occurs: Alert and Block. Alert generates a log and notification without stopping the traffic, while Block prevents the data from being transmitted. These actions allow administrators to monitor or enforce policies on sensitive data. Other actions like Allow, Reset Client, and Continue are not available in Data Filtering profiles, making Alert and Block the correct choices for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Continue

    Why it's wrong here

    Continue is not an action in a Data Filtering profile. The profile actions are limited to Alert and Block. 'Continue' might be confused with the 'Allow' action in Security policies, but it is not applicable here. The administrator cannot configure a Data Filtering profile to 'Continue' when sensitive data is detected; they must choose to either alert or block.

  • ✗

    Reset Client

    Why it's wrong here

    Reset Client is an action available in some security profiles, such as Vulnerability Protection, but it is not a standard action in a Data Filtering profile. Data Filtering profiles typically offer Alert and Block actions. Reset Client would terminate the client-side connection, but it is not used for data filtering. Therefore, it is not a valid choice for this scenario.

  • ✓

    Alert

    Why this is correct

    The Alert action in a Data Filtering profile generates a log entry and an alert but does not block the traffic. It is useful for monitoring and auditing sensitive data patterns without disrupting business operations. In this scenario, the administrator can use Alert to identify potential data leaks and then decide whether to escalate to blocking. It allows visibility into what data is being transmitted.

  • ✓

    Block

    Why this is correct

    The Block action in a Data Filtering profile prevents the transmission of the matched data by dropping the session or resetting the connection. It effectively stops the sensitive information from leaving the network. This is appropriate when the administrator wants to enforce a strict policy against data exfiltration. The action can be configured for specific data patterns and applications.

  • ✗

    Allow

    Why it's wrong here

    Allow is not a valid action within a Data Filtering profile. Data Filtering profiles are designed to detect and respond to sensitive data patterns; they do not have an 'allow' action because the default behavior is to permit traffic unless a match triggers a configured action. The administrator would not use 'Allow' to block data; instead, they would use 'Block' or 'Alert'.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.