Courseiva
easyMultiple Choice

PCNSA Practice Question: Provide internet access to employees while…

An administrator needs to provide internet access to employees while blocking access to social media sites. Which feature should be used to identify and block social media traffic?

⚠ Common exam trap

Many candidates confuse SSL Decryption (which enables visibility into encrypted traffic) with the actual blocking mechanism, not realizing that URL Filtering profiles are the correct tool for category-based blocking without requiring decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

URL Filtering profile to block the Social Networking category.

A URL Filtering profile allows the administrator to block access to specific categories of websites, such as Social Networking. By applying this profile to a security policy rule that governs internet access, the firewall can identify and block HTTP/HTTPS traffic to social media sites based on their URL category, without needing to decrypt or inspect the content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    URL Filtering profile to block the Social Networking category.

    Why this is correct

    A URL Filtering profile inspects the requested URL against the Social Networking category and applies a block action, satisfying the requirement to deny social media while permitting general internet access. It identifies traffic by destination URL rather than IP or port.

  • ✗

    SSL Decryption policy to decrypt traffic to social media.

    Why it's wrong here

    SSL decryption reveals encrypted payloads but does not itself identify or block applications; a decryption policy alone permits the traffic. It is the prerequisite enabling App-ID to classify encrypted social media sessions, and would be correct only where traffic is encrypted and inspection is otherwise impossible.

  • ✗

    QoS policy to limit bandwidth to social media sites.

    Why it's wrong here

    QoS policies shape bandwidth and priority; they cannot identify social media applications nor deny them, so access continues at a reduced rate. QoS is correct when the goal is guaranteeing latency or throughput for business-critical traffic, not enforcing a block.

  • ✗

    File blocking profile to block executable files from social media.

    Why it's wrong here

    File blocking profiles act on file types within permitted sessions, so social media pages and apps still load; only executables are stopped. File blocking is correct when the requirement is preventing malware downloads over allowed applications, not denying the application itself.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.