Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A security analyst observes that users are downloading executable files from a cloud storage service, which is a known vector for malware. The company policy dictates that all executable file downloads from unknown or unapproved cloud storage services must be blocked. Which Content-ID component on the Palo Alto Networks firewall should be configured to enforce this policy?
- AFile Blocking Profile
- BVulnerability Protection Profile
- CAntivirus Profile
- DURL Filtering Profile
Show answer & explanationAnswer & explanation
Correct answer: A. File Blocking Profile
The requirement is to block specific file types (executables) based on their content, regardless of the URL category or if they are detected as malware. A File Blocking Profile directly addresses this by allowing administrators to block or alert on specific file types, such as executables, archives, or multimedia files.
Why the other options are wrong
- B. Vulnerability Protection Profile prevents attacks that exploit system vulnerabilities, not the transfer of specific file types.
- C. Antivirus Profile detects and blocks known malware signatures, but doesn't block legitimate, but policy-violating, executable files from unapproved sources.
- D. URL Filtering Profile blocks access to entire categories of websites, not specific file types within those sites.
File Blocking Profile
A Content-ID security profile used to control the transfer of specific file types across the network, preventing unwanted or risky files from entering or leaving.
- File Blocking Profiles can block or alert on file types (e.g., executables, archives, multimedia).
- File types are identified by their true type, not just file extension.
- Can be applied to specific applications or directions (upload/download).
Memory trick: Content-ID: Scan the stream, block the bad, protect the team.