PCNSA App-ID and Content-ID Practice Question
A security administrator wants to block all traffic using the BitTorrent protocol regardless of port. Which method should they use?
⚠ Common exam trap
Watch out — candidates often default to port-based blocking (Option D) or think URL Filtering (Option A) can block application traffic, failing to recognize that App-ID is the only method that can identify and block applications like BitTorrent irrespective of port or encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security rule with Application set to 'bittorrent' and Action set to 'Deny'.
Palo Alto Networks firewalls use App-ID to identify applications like BitTorrent by their unique signatures, regardless of port or encryption. By creating a security rule with the application set to 'bittorrent' and action set to 'Deny', the firewall blocks all BitTorrent traffic even if it uses non-standard ports or tries to masquerade as other protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use URL Filtering to block BitTorrent.
Why it's wrong here
URL Filtering classifies web destinations, not peer-to-peer application protocols, so BitTorrent traffic on non-web ports bypasses it entirely. It is tempting because it blocks torrent indexing sites, and it would be the right control for preventing users from browsing known torrent repositories.
- ✓
Create a security rule with Application set to 'bittorrent' and Action set to 'Deny'.
Why this is correct
Palo Alto Networks App-ID identifies BitTorrent by its traffic characteristics rather than port, so a security rule matching the bittorrent application with a Deny action blocks the protocol even when it uses non-standard or randomised ports.
- ✗
Use Data Filtering to block BitTorrent traffic.
Why it's wrong here
Data Filtering matches patterns in file transfers and is not designed to identify BitTorrent application traffic across arbitrary ports. It is tempting because it inspects payload content, and it would be correct for blocking sensitive data patterns such as credit card numbers leaving the network.
- ✗
Block the commonly used ports for BitTorrent.
Why it's wrong here
BitTorrent evades static port blocking by negotiating dynamic ports and using encryption, so port-based rules miss most traffic. Blocking known ports is tempting because it is quick and catches default configurations, and it would suffice only where clients cannot randomise ports.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.