You want to know how to block specific files types from user access in Cloud Secure Web Gateway (formerly known as WSS).
[Image 1] Threat protection Add rule (Group B)
Important note: File based policies are intended to be put in the Threat Protection layer rather than the Content Filtering / Acceptable Use layer.
Specifically advanced verdicts available in the Content Filtering rules ("Allow with Coach" and "Block with Password Override") are designed to be applied to web-pages so that the coaching or password override page can be returned and displayed to the user.