Courseiva
App-ID and Content-ID →mediumMultiple Choice

PCNSA App-ID and Content-ID Practice Question

A security administrator notices that a SaaS application is allowed by the security policy, but the firewall is not decrypting the traffic. Without decryption, which Content-ID feature can still identify and control the application's use based on the server certificate?

⚠ Common exam trap

The trap here is assuming that any Content-ID feature can inspect encrypted traffic without decryption, when only certificate-based App-ID can identify applications from the certificate metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate-based App-ID

Certificate-based App-ID is designed to identify applications by examining the server certificate presented during the TLS handshake, without requiring decryption. This allows enforcement of security policies for SaaS applications while maintaining end-to-end encryption. Decryption profiles, File Blocking, and Data Filtering all require visibility into the payload, which is not available when traffic remains encrypted. Thus, certificate-based App-ID is the correct Content-ID feature for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Certificate-based App-ID

    Why this is correct

    Certificate-based App-ID allows the firewall to identify applications by inspecting the server certificate during the TLS handshake, even when traffic is not decrypted. This enables policy enforcement for SaaS applications without breaking encryption. It is a Content-ID capability that extracts the certificate fields and maps them to an App-ID, satisfying the requirement to control the application while preserving privacy.

  • ✗

    SSL Decryption profile

    Why it's wrong here

    An SSL Decryption profile defines how the firewall handles decryption, such as blocking expired certificates or untrusted issuers. It does not identify applications from certificates when traffic remains encrypted. The scenario asks for a Content-ID feature that can still control the application without decryption, so a decryption profile is not the mechanism that performs identification.

  • ✗

    File Blocking profile

    Why it's wrong here

    A File Blocking profile controls the transfer of files based on file type and direction, but it requires the firewall to see the file contents. Without decryption, the firewall cannot inspect the file payload to enforce the profile. Therefore, it cannot identify or control the SaaS application based on the server certificate in this scenario.

  • ✗

    Data Filtering profile

    Why it's wrong here

    A Data Filtering profile scans traffic for patterns such as credit card numbers or social security numbers. It operates on decrypted payloads and cannot inspect encrypted traffic. Since the traffic is not decrypted, the Data Filtering profile will not see the data patterns, so it cannot identify or control the application as required.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.