PCNSA Managing Objects Practice Question
A large enterprise uses dynamic address groups based on tags to manage firewall policies. The administrator notices that a specific address object is being incorrectly included in a dynamic address group that should only contain servers from a different region. What could be the reason?
⚠ Common exam trap
Many candidates assume dynamic groups use 'match all' by default or that tag conflicts are impossible, but the 'match any' operator is common and can cause objects with overlapping tags to be included in unintended groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The address object has multiple tags including the wrong one
Dynamic address groups in Palo Alto Networks firewalls use tags to automatically include or exclude address objects. If an address object has multiple tags and one of them matches the tag criteria defined for the dynamic group, the object will be included even if it also has tags that would otherwise place it in a different region. This is the most likely cause of the incorrect inclusion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The group is configured as static
Why it's wrong here
A static group's membership is fixed by explicit object entries, so it would not dynamically pull in a region-mismatched server. It is tempting because static groups are the alternative membership model, but the stem describes tag-driven dynamic behaviour, so static configuration cannot explain the inclusion.
- ✗
The dynamic group uses 'match all' and the object lacks some tags
Why it's wrong here
'Match all' requires every listed tag, so an object missing tags would be excluded, not wrongly included. It is tempting because 'match all' versus 'match any' is the tag-matching axis, but the observed symptom is over-inclusion, which only 'match any' with a shared tag produces.
- ✗
The administrator added the object directly to the group
Why it's wrong here
Dynamic address groups contain members solely by tag-match criteria; objects cannot be added directly, so this mechanism does not exist in PAN-OS. It is tempting because static groups do accept manual membership, but the stem specifies a dynamic group, where membership is evaluated from tags alone.
- ✓
The address object has multiple tags including the wrong one
Why this is correct
Dynamic address groups match members purely by tag, so any address object carrying the group's tag is included automatically. If that object also holds the other region's tag, it joins both groups, explaining the incorrect inclusion described in the stem.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.