Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security analyst observes that users are downloading executable files from a cloud storage service, which is a known vector for malware. The company policy dictates that all executable file downloads from unknown or unapproved cloud storage services must be blocked. Which Content-ID component on the Palo Alto Networks firewall should be configured to enforce this policy?

  1. AFile Blocking Profile
  2. BVulnerability Protection Profile
  3. CAntivirus Profile
  4. DURL Filtering Profile
Show answer & explanation

Correct answer: A. File Blocking Profile

The requirement is to block specific file types (executables) based on their content, regardless of the URL category or if they are detected as malware. A File Blocking Profile directly addresses this by allowing administrators to block or alert on specific file types, such as executables, archives, or multimedia files.

Why the other options are wrong

  • B. Vulnerability Protection Profile prevents attacks that exploit system vulnerabilities, not the transfer of specific file types.
  • C. Antivirus Profile detects and blocks known malware signatures, but doesn't block legitimate, but policy-violating, executable files from unapproved sources.
  • D. URL Filtering Profile blocks access to entire categories of websites, not specific file types within those sites.

File Blocking Profile

A Content-ID security profile used to control the transfer of specific file types across the network, preventing unwanted or risky files from entering or leaving.

  • File Blocking Profiles can block or alert on file types (e.g., executables, archives, multimedia).
  • File types are identified by their true type, not just file extension.
  • Can be applied to specific applications or directions (upload/download).

Memory trick: Content-ID: Scan the stream, block the bad, protect the team.

More Security Policy Configuration questions