Courseiva
App-ID and Content-ID →hardMultiple Choice

PCNSA App-ID and Content-ID Practice Question

After a security policy change, users complain that they cannot upload files to a custom web application. The rule allows the custom application 'webapp' and Content-ID is enabled. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often assume the issue is with App-ID misidentification or SSL decryption, but the question explicitly states the application is allowed and Content-ID is enabled, pointing directly to a file blocking profile as the cause of the upload failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A file blocking profile is blocking the upload.

A file blocking profile, when enabled with Content-ID, can block uploads of specific file types even if the application itself is allowed. In this scenario, the rule permits the custom application 'webapp' and Content-ID is enabled, so the most likely reason for upload failure is that a file blocking profile is configured to block the file type being uploaded, not an issue with App-ID or SSL decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application 'webapp' is not allowed due to an application override.

    Why it's wrong here

    An application override forces traffic to a specified App-ID rather than blocking it, so it would not deny 'webapp' when the rule allows that application. It is tempting because overrides change App-ID classification, and it would be correct if traffic were being matched to the wrong application.

  • ✗

    SSL decryption is not enabled.

    Why it's wrong here

    SSL decryption affects visibility into encrypted sessions, but the policy already permits 'webapp' by App-ID, so uploads are not blocked for that reason. It is tempting because decryption is needed for Content-ID inspection, and it would be correct if the application were unidentified due to encrypted traffic.

  • ✓

    A file blocking profile is blocking the upload.

    Why this is correct

    With Content-ID enabled, the firewall inspects the upload and a file blocking profile applied to the matching rule drops the transfer if the file type is blocked. The application itself is permitted, so the file blocking profile is the likely cause.

  • ✗

    App-ID is not identifying the application correctly.

    Why it's wrong here

    App-ID correctly identifying 'webapp' would permit the traffic, so misidentification is not the likely cause when the rule already names that custom application. It is tempting because App-ID underpins policy matching, and it would be correct if the application were being classified as unknown-tcp or a different App-ID.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.