Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A financial institution has a strict compliance requirement to prevent the accidental or malicious exfiltration of sensitive customer data (e.g., credit card numbers, social security numbers) over any outbound application. Which Content-ID feature within a security profile should be configured to address this requirement most effectively?

  1. AData Filtering Profiles
  2. BFile Blocking Profiles
  3. CVulnerability Protection Profiles
  4. DAnti-Spyware Profiles
Show answer & explanation

Correct answer: A. Data Filtering Profiles

Data Filtering Profiles are specifically designed to prevent the transfer of sensitive information based on predefined patterns (like credit card numbers, SSNs) or custom patterns. This directly addresses the requirement for preventing data exfiltration.

Why the other options are wrong

  • B. File Blocking Profiles prevent the transfer of specific *file types*, not specific data patterns within files or application streams.
  • C. Vulnerability Protection Profiles protect against exploits, not sensitive data leakage.
  • D. Anti-Spyware Profiles detect and block spyware, not sensitive data patterns.

Data Filtering Profile

A Data Filtering Profile inspects content for sensitive data patterns (e.g., credit card numbers, SSNs) and can apply actions like block or alert to prevent data exfiltration.

  • Part of Content-ID.
  • Uses predefined or custom data patterns.
  • Crucial for data loss prevention (DLP) efforts.

Memory trick: Data Filtering: Filter What Goes Out, Not Just How.

More Security Policy Configuration questions