Courseiva
Managing Objects →hardMultiple Select

PCNSA Managing Objects Practice Question

An administrator is configuring a Dynamic Address Group (DAG) to automatically include all servers that have the tag 'WebServer'. The DAG will be used in a security policy. Which two of the following statements are true regarding the configuration and behavior of this DAG? (Choose two.)

⚠ Common exam trap

The trap here is thinking that DAGs require a User-ID agent or use regex filters; actually, they rely on tag-based filters and do not need User-ID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The DAG can be referenced in a security policy as a source or destination address.

Dynamic Address Groups automatically update their membership based on tag changes, and they can be used in security policies as source or destination addresses. These two characteristics make DAGs powerful for dynamic environments where server roles or IPs change frequently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The DAG can be referenced in a security policy as a source or destination address.

    Why this is correct

    Dynamic Address Groups are address objects themselves and can be used in security policies just like static address groups. They can be specified in the source or destination field of a rule, enabling dynamic enforcement based on group membership.

  • ✗

    The DAG requires the firewall to be connected to a User-ID agent to function.

    Why it's wrong here

    Dynamic Address Groups can use tags from various sources, including static tags, EDLs, and VM monitoring. They do not inherently require a User-ID agent. User-ID is for mapping IPs to users, not for DAG functionality. So this statement is false.

  • ✗

    The DAG can only contain IP addresses from a single subnet.

    Why it's wrong here

    Dynamic Address Groups can include any address objects regardless of subnet. The membership is based on tags or filters, not on IP subnet. So a DAG can contain IPs from multiple subnets, making this statement false.

  • ✓

    The DAG membership is updated automatically when the tags on address objects change.

    Why this is correct

    Dynamic Address Groups use match filters that can reference tags. When an address object's tags change, the firewall re-evaluates the DAG filter and updates membership accordingly. This dynamic behavior is the key advantage of DAGs, allowing security policies to adapt without manual intervention.

  • ✗

    The DAG filter must be written in a specific regular expression syntax.

    Why it's wrong here

    DAG filters use a simple syntax with tags and logical operators (and, or, not), not regular expressions. For example, 'WebServer' or 'WebServer and Production'. Regular expressions are used in other contexts like URL filtering, but not for DAG filters.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.