PCNSA Managing Objects Practice Question
A security administrator is configuring an External Dynamic List (EDL) for IP addresses that will be used in a security policy to block malicious traffic. The EDL is hosted on an internal web server at https://edl.example.com/blocklist. The administrator wants to ensure that the firewall can retrieve the list and that it is updated every hour. Which configuration is required for the EDL to function correctly?
⚠ Common exam trap
The trap here is focusing on certificate authentication or URL category configuration, while overlooking the basic network requirements of DNS resolution and routing to the EDL source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and ensure that the firewall can resolve the DNS name and has a route to the web server.
For an EDL to be retrieved, the firewall must be able to resolve the domain name and reach the server. The update interval is set in the EDL configuration. Certificate authentication is only needed if the server requires it and the firewall does not trust the certificate. Thus, ensuring DNS resolution and network connectivity is fundamental.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and ensure that the firewall has a valid certificate to authenticate to the web server.
Why it's wrong here
While certificate authentication might be needed if the server requires it, it is not a mandatory requirement for all EDLs. The EDL source can be HTTP or HTTPS, and if HTTPS is used, the firewall may need to trust the server's certificate, but this is not always the case. The key requirements are the correct URL and update interval, but certificate authentication is not always required.
- ✗
Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and configure a custom URL category to include the EDL.
Why it's wrong here
A custom URL category is used for URL filtering, not for IP address EDLs. IP EDLs are used directly in security policies as source or destination addresses. Creating a custom URL category would not make the EDL functional for IP blocking. The EDL must be referenced as an address object in the policy.
- ✓
Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and ensure that the firewall can resolve the DNS name and has a route to the web server.
Why this is correct
For the firewall to retrieve the EDL, it must be able to resolve the hostname to an IP address and have network connectivity to the server. The EDL configuration includes the source URL and update interval. The firewall uses its management interface or a specified interface for EDL retrieval, so DNS and routing are essential. Certificate authentication is not always required, especially if the server uses a publicly trusted certificate.
- ✗
Configure the EDL with source URL http://edl.example.com/blocklist, set the recurring update to hourly, and add the EDL to a security policy as a source address.
Why it's wrong here
Using HTTP instead of HTTPS is insecure and not recommended, but the main issue is that the EDL must be referenced in a policy as a source or destination address, but adding it as a source address is not the only requirement. The EDL must be used in a policy to take effect, but the question asks for the configuration required for the EDL to function correctly, which includes retrieval. The update interval and URL are correct, but HTTP is not best practice; however, the critical flaw is that the EDL must be used in a policy, but that is not the primary configuration for retrieval.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.