Courseiva
Managing Objects →hardMultiple Choice

PCNSA Managing Objects Practice Question

A large enterprise uses dynamic address groups based on tags to manage firewall policies. The administrator notices that a specific address object is being incorrectly included in a dynamic address group that should only contain servers from a different region. What could be the reason?

⚠ Common exam trap

Many candidates assume dynamic groups use 'match all' by default or that tag conflicts are impossible, but the 'match any' operator is common and can cause objects with overlapping tags to be included in unintended groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The address object has multiple tags including the wrong one

Dynamic address groups in Palo Alto Networks firewalls use tags to automatically include or exclude address objects. If an address object has multiple tags and one of them matches the tag criteria defined for the dynamic group, the object will be included even if it also has tags that would otherwise place it in a different region. This is the most likely cause of the incorrect inclusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The group is configured as static

    Why it's wrong here

    A static group's membership is fixed by explicit object entries, so it would not dynamically pull in a region-mismatched server. It is tempting because static groups are the alternative membership model, but the stem describes tag-driven dynamic behaviour, so static configuration cannot explain the inclusion.

  • ✗

    The dynamic group uses 'match all' and the object lacks some tags

    Why it's wrong here

    'Match all' requires every listed tag, so an object missing tags would be excluded, not wrongly included. It is tempting because 'match all' versus 'match any' is the tag-matching axis, but the observed symptom is over-inclusion, which only 'match any' with a shared tag produces.

  • ✗

    The administrator added the object directly to the group

    Why it's wrong here

    Dynamic address groups contain members solely by tag-match criteria; objects cannot be added directly, so this mechanism does not exist in PAN-OS. It is tempting because static groups do accept manual membership, but the stem specifies a dynamic group, where membership is evaluated from tags alone.

  • ✓

    The address object has multiple tags including the wrong one

    Why this is correct

    Dynamic address groups match members purely by tag, so any address object carrying the group's tag is included automatically. If that object also holds the other region's tag, it joins both groups, explaining the incorrect inclusion described in the stem.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.