PCNSA App-ID and Content-ID Practice Question
A security administrator wants to allow access to a SaaS application but block specific high-risk functions within that application, such as file uploads. The application uses HTTP and HTTPS. Which Palo Alto Networks feature should the administrator use to granularly control application functions?
⚠ Common exam trap
The trap here is thinking that application filters or Data Filtering can control specific functions within an application, but only App-ID's function-level identification provides that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
App-ID with application functions
App-ID can identify not only the application but also specific functions within it, such as file upload or posting. By using these application functions in security policy rules, the administrator can allow the SaaS application while blocking high-risk actions like file uploads. This provides granular control without blocking the entire application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
App-ID with application functions
Why this is correct
App-ID includes the ability to identify and control specific functions within an application, known as application functions or sub-functions. For example, some SaaS applications have functions like 'file-sharing' or 'upload'. By using these in security policy, the administrator can allow the application but block specific high-risk functions, providing granular control.
- ✗
App-ID with application filters
Why it's wrong here
Application filters are used to group applications based on characteristics like category, risk, and technology. They do not provide control over specific functions within an application. While useful for policy grouping, they cannot block file uploads within a SaaS application. The administrator needs a feature that inspects and controls application behavior.
- ✗
Content-ID with Data Filtering
Why it's wrong here
Data Filtering inspects content for sensitive data patterns, such as credit card numbers, but it does not control application functions like file uploads. It is used to prevent data leakage, not to restrict specific actions within an application. Therefore, it is not the right tool for blocking file uploads based on application function.
- ✗
App-ID with application override
Why it's wrong here
Application override changes the App-ID for specific traffic, typically to force a custom application or bypass identification. It does not provide granular control over functions within an application. Using override would not help block file uploads; it would only alter how the application is identified.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.