Courseiva
App-ID and Content-ID →mediumMultiple Choice

PCNSA App-ID and Content-ID Practice Question

A user reports that they are unable to download executable files from the internet. The firewall security rule allows the application. What should the administrator check first?

⚠ Common exam trap

Candidates often confuse file blocking with URL filtering or application control, assuming that allowing the application automatically permits all file transfers, but Content-ID file blocking operates independently at the file level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file blocking profile for the rule.

The user cannot download executable files, which is a specific file type. The file blocking profile is the Content-ID feature that controls file transfer based on type, regardless of the application being allowed. Since the security rule permits the application, the administrator should first check the file blocking profile attached to that rule to see if it blocks 'executable' files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SSL decryption policy.

    Why it's wrong here

    SSL decryption governs whether encrypted sessions are inspected; it does not itself block executable downloads. It is tempting because undecrypted HTTPS hides file contents from other profiles, so it is the right check when threats evade inspection, not when a permitted application's download is blocked.

  • ✗

    The vulnerability protection profile.

    Why it's wrong here

    Vulnerability protection profiles inspect traffic for exploits such as buffer overflows and code-execution attempts; they do not block file downloads by category. It is tempting because executables carry risk, but this profile suits detecting attacks against vulnerable services, not preventing a user from saving an .exe.

  • ✓

    The file blocking profile for the rule.

    Why this is correct

    File blocking profiles inspect file types within allowed applications, so executables can be blocked even when the application itself is permitted. Checking this profile first identifies whether a file-type restriction, rather than the security rule, is preventing the download.

  • ✗

    The URL filtering category for 'executables'.

    Why it's wrong here

    URL filtering classifies web destinations, not individual file types, so an executable fetched from an allowed site passes. It is tempting because blocking categories is a common control, but it suits restricting access to sites such as gambling or malware hosts, not preventing .exe downloads.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.