PCNSA Managing Objects Practice Question
An administrator is configuring a Dynamic Address Group (DAG) that uses tags to automatically include members. The administrator wants to ensure that the DAG is populated correctly. Which two actions are required to make a firewall register an IP address as a member of the DAG? (Choose two.)
⚠ Common exam trap
The trap here is thinking that DAGs require manual IP entry or that they use DNS, when they actually rely on external tag registration and filter matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall must receive the tag information via an external source, such as a User-ID agent or a syslog listener.
Dynamic Address Groups are populated based on tags that are registered with the firewall. The two essential actions are: the firewall must receive tag information from an external source (like User-ID agent or syslog), and the DAG filter must reference those tags. Without both, the group will not be populated. Manual addition or DNS resolution are not part of the DAG mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall must receive the tag information via an external source, such as a User-ID agent or a syslog listener.
Why this is correct
Dynamic Address Groups rely on tags that are registered with the firewall. These tags can be learned through various methods, including User-ID agents, syslog listeners, or the XML API. Without a source providing the tag-to-IP mapping, the firewall cannot know which IPs belong to the group. Therefore, receiving tag information from an external source is essential for the DAG to be populated.
- ✗
The administrator must enable the 'Dynamic Group' option in the security policy rule.
Why it's wrong here
There is no such option as 'Dynamic Group' in a security policy rule. Dynamic Address Groups are referenced just like static groups in policy rules. The dynamic nature is handled by the group object itself, not by a policy setting. Enabling a specific option in the rule is not required and does not exist in PAN-OS.
- ✗
The administrator must manually add each IP address as a static member of the DAG.
Why it's wrong here
Manually adding static members defeats the purpose of a Dynamic Address Group, which is designed to automatically update based on tags. Static members are used in static address groups, not dynamic ones. If you manually add IPs, they will not be dynamically updated when tags change, and the group will not function as intended.
- ✓
The DAG filter must reference the tags that are registered for the IP addresses.
Why this is correct
The DAG is defined with a filter expression that matches tags. For an IP address to be included, it must have a tag that matches the filter. For example, if the filter is 'WebServer', only IPs with that tag will be members. Therefore, the filter must reference the correct tags that are registered for the desired IPs. This is a critical configuration step.
- ✗
The firewall must be configured to resolve the IP addresses to hostnames via DNS.
Why it's wrong here
DNS resolution is not used for DAG membership. DAGs are based on tags, not hostnames. While FQDN address objects use DNS, dynamic groups do not. The firewall does not need to resolve IPs to hostnames to populate a DAG; it only needs the tag-to-IP mappings. DNS configuration would not help in this scenario.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.