PCNSA App-ID and Content-ID Practice Question
A security administrator wants to prevent users from posting sensitive data, such as social security numbers, to web forms on external websites. The administrator has enabled SSL decryption for outbound traffic. Which Content-ID feature should be configured to detect and block this activity?
⚠ Common exam trap
The trap here is assuming that URL Filtering or File Blocking can inspect data content, when only Data Filtering is designed for pattern-based sensitive data detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Filtering profile
Data Filtering profiles are specifically designed to detect and control sensitive data patterns, including social security numbers, in web traffic. When SSL decryption is enabled, the firewall can inspect the content of web forms and apply the Data Filtering profile to block or alert on the transmission. This is the correct feature to prevent data leakage through web forms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus profile
Why it's wrong here
Antivirus profiles scan for viruses and malware in files and traffic, not for sensitive data patterns like social security numbers. They do not inspect form fields for data leakage. Therefore, an Antivirus profile would not detect or block the posting of sensitive information.
- ✗
File Blocking profile
Why it's wrong here
File Blocking profiles control the transfer of files based on file type, not the content within web form submissions. Social security numbers entered into a web form are not files, so File Blocking would not detect or block them. This feature is ineffective for preventing data leakage through form fields.
- ✓
Data Filtering profile
Why this is correct
Data Filtering profiles are designed to detect and control sensitive data patterns, such as social security numbers and credit card numbers, in web forms and other traffic. With SSL decryption enabled, the firewall can inspect the content and apply the Data Filtering profile to block or alert on the transmission. This directly addresses the requirement to prevent posting sensitive data.
- ✗
URL Filtering profile
Why it's wrong here
URL Filtering profiles block or allow access to websites based on URL categories, not based on the data content being submitted. While it could block entire sites, it cannot detect social security numbers within a form. The requirement is to prevent posting sensitive data, not to block websites categorically.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.