PCNSA App-ID and Content-ID Practice Question
A security administrator is configuring a File Blocking profile to prevent users from downloading executable files from the internet. The administrator wants to ensure that the firewall blocks only the download direction and not the upload direction, while still logging the event. Which configuration should be used?
⚠ Common exam trap
Many candidates confuse the 'alert' and 'continue' actions with 'block', or applying the block to all file types or both directions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the File Blocking profile action to 'block' for the 'exe' file type in the download direction only.
A File Blocking profile can be configured with specific actions per file type and direction. To block only executable downloads while logging, the action for 'exe' should be set to 'block' in the download direction. This prevents executable files from being downloaded, logs the event, and leaves uploads and other file types unaffected. This precise configuration meets the security requirement without unnecessary restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the File Blocking profile action to 'block' for all file types in the download direction.
Why it's wrong here
Blocking all file types in the download direction is overly broad and would prevent legitimate downloads such as documents, images, and software updates. The administrator specifically wants to block executable files, not all files. This would cause significant operational disruption and does not align with the stated goal of blocking only executables.
- ✗
Set the File Blocking profile action to 'alert' for the 'exe' file type in both directions.
Why it's wrong here
Setting the action to 'alert' only logs the event and does not block the file transfer. The requirement is to block downloads, so 'alert' is insufficient. Additionally, applying it to both directions would not specifically target downloads. This configuration fails to prevent executable downloads and may allow malicious files to reach users.
- ✗
Set the File Blocking profile action to 'continue' for the 'exe' file type in the upload direction only.
Why it's wrong here
The 'continue' action allows the file to pass while logging it, and applying it to uploads does not block downloads. This would not prevent users from downloading executables, leaving the network vulnerable. The requirement is to block downloads, so this configuration is ineffective and misdirected.
- ✓
Set the File Blocking profile action to 'block' for the 'exe' file type in the download direction only.
Why this is correct
File Blocking profiles allow you to specify the action (block, alert, continue) per file type and direction. Setting 'block' for 'exe' in the download direction ensures that executable files are blocked when downloaded, while uploads are not affected. Logging is automatically generated for blocked files, satisfying the logging requirement. This directly meets the administrator's needs without overblocking.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.