PCNSA App-ID and Content-ID Practice Question
After a security policy change, users complain that they cannot upload files to a custom web application. The rule allows the custom application 'webapp' and Content-ID is enabled. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often assume the issue is with App-ID misidentification or SSL decryption, but the question explicitly states the application is allowed and Content-ID is enabled, pointing directly to a file blocking profile as the cause of the upload failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A file blocking profile is blocking the upload.
A file blocking profile, when enabled with Content-ID, can block uploads of specific file types even if the application itself is allowed. In this scenario, the rule permits the custom application 'webapp' and Content-ID is enabled, so the most likely reason for upload failure is that a file blocking profile is configured to block the file type being uploaded, not an issue with App-ID or SSL decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application 'webapp' is not allowed due to an application override.
Why it's wrong here
An application override forces traffic to a specified App-ID rather than blocking it, so it would not deny 'webapp' when the rule allows that application. It is tempting because overrides change App-ID classification, and it would be correct if traffic were being matched to the wrong application.
- ✗
SSL decryption is not enabled.
Why it's wrong here
SSL decryption affects visibility into encrypted sessions, but the policy already permits 'webapp' by App-ID, so uploads are not blocked for that reason. It is tempting because decryption is needed for Content-ID inspection, and it would be correct if the application were unidentified due to encrypted traffic.
- ✓
A file blocking profile is blocking the upload.
Why this is correct
With Content-ID enabled, the firewall inspects the upload and a file blocking profile applied to the matching rule drops the transfer if the file type is blocked. The application itself is permitted, so the file blocking profile is the likely cause.
- ✗
App-ID is not identifying the application correctly.
Why it's wrong here
App-ID correctly identifying 'webapp' would permit the traffic, so misidentification is not the likely cause when the rule already names that custom application. It is tempting because App-ID underpins policy matching, and it would be correct if the application were being classified as unknown-tcp or a different App-ID.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.