Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy

A security technician observes that internal users are frequently downloading executable files (.exe) from legitimate cloud storage services, posing a potential malware risk. The company wants to prevent the download of executable files from the internet while still allowing access to the cloud storage services. Which security profile should be configured and applied to enforce this policy?

  1. AFile Blocking Profile
  2. BURL Filtering Profile
  3. CAnti-Spyware Profile
  4. DVulnerability Protection Profile
Show answer & explanation

Correct answer: A. File Blocking Profile

A File Blocking Profile is specifically designed to prevent the transfer of certain file types, such as executables (.exe), across the firewall. This directly addresses the requirement to block executable downloads while allowing access to the cloud storage service itself.

Why the other options are wrong

  • B. URL Filtering controls access to websites based on categories, not specific file types within those websites.
  • C. Anti-Spyware Profile detects and blocks spyware, not general file types.
  • D. Vulnerability Protection Profile protects against known exploits, not the downloading of specific file types.

File Blocking Profile

A File Blocking Profile is a security profile that prevents the transfer of specific file types (e.g., executables, archives) in either upload or download directions.

  • Part of Content-ID.
  • Configured with actions like block, alert, or continue.
  • Helps prevent malware introduction and data exfiltration.

Memory trick: File Blocking: Block the Binary.

More Security Policy Configuration questions