PCNSA App-ID and Content-ID Practice Question
A security administrator needs to ensure that users cannot upload files containing malware to cloud storage applications. The administrator has enabled SSL decryption and wants to use WildFire to inspect files. Which configuration is required to submit files to WildFire for analysis?
⚠ Common exam trap
The trap here is assuming that an Antivirus profile or File Blocking profile automatically submits files to WildFire, when a separate WildFire Analysis profile is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a WildFire Analysis profile and apply it to the Security policy rule that allows the cloud storage applications.
To submit files to WildFire for analysis, a WildFire Analysis profile must be configured and applied to the relevant Security policy rule. This profile defines which file types and directions are sent to WildFire. With SSL decryption enabled, the firewall can inspect encrypted uploads to cloud storage and forward files to WildFire. Other profiles like File Blocking, Antivirus, or Data Filtering do not provide WildFire submission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Data Filtering profile to inspect file contents for malware patterns.
Why it's wrong here
Data Filtering profiles are for detecting sensitive data patterns, not malware. They do not submit files to WildFire or perform malware analysis. Using a Data Filtering profile would not fulfill the requirement to inspect files for malware via WildFire, and it might cause false positives for legitimate data.
- ✓
Configure a WildFire Analysis profile and apply it to the Security policy rule that allows the cloud storage applications.
Why this is correct
A WildFire Analysis profile specifies which file types and directions to submit to WildFire for analysis. Applying it to the Security policy rule that permits the cloud storage applications ensures that files uploaded to those applications are inspected. With SSL decryption enabled, the firewall can extract files from the encrypted traffic and send them to WildFire. This configuration directly meets the requirement.
- ✗
Configure an Antivirus profile to scan file uploads and block malware.
Why it's wrong here
An Antivirus profile uses signatures to detect known malware but does not submit files to WildFire for dynamic analysis. While it can block known threats, it cannot detect zero-day malware that WildFire can identify. The requirement specifically mentions using WildFire, so an Antivirus profile alone is insufficient.
- ✗
Configure a File Blocking profile to block all file uploads to cloud storage applications.
Why it's wrong here
A File Blocking profile can block files based on type but does not submit files to WildFire for analysis. It would prevent all uploads of specified types, which is not the goal. The administrator wants to use WildFire to inspect files for malware, not simply block them. This approach lacks the dynamic analysis provided by WildFire.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.