PCNSA Managing Objects Practice Question
An administrator is creating address objects in PAN-OS and needs to ensure that they can be used in security policies to identify specific sources and destinations. Which two of the following are valid address object types that can be directly referenced in a security policy rule? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse other object types, such as Service or Region, with address objects that can be used in the source and destination fields of a security policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FQDN
IP Netmask and FQDN are both valid address object types that can be directly referenced in security policy rules. IP Netmask defines a subnet, and FQDN resolves a domain name to IPs. The other options are not address objects: Region is used for geographic targeting, while Service and Application Filter are used in other policy fields. Thus, the correct choices are IP Netmask and FQDN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Region
Why it's wrong here
A Region object in PAN-OS represents a geographic region and is used in URL filtering and other policy types, but it is not an address object type that can be directly referenced in a security policy rule's source or destination field. Security policies match on IP addresses, not geographic regions. Therefore, Region is not a valid address object for this purpose.
- ✗
Service
Why it's wrong here
A Service object defines protocol and port information, not IP addresses. It is used in the Service field of a security policy, not in the Source or Destination address fields. Therefore, it is not an address object and cannot be used where an address object is expected. The question specifically asks for address object types, so Service is incorrect.
- ✗
Application Filter
Why it's wrong here
An Application Filter is a group of applications used in the Application field of a security policy. It does not represent IP addresses and is not an address object. It cannot be referenced in the Source or Destination fields. Therefore, it is not a valid address object type for the purpose described.
- ✓
FQDN
Why this is correct
An FQDN address object resolves a domain name to IP addresses and can be used in security policies. When referenced, the firewall resolves the FQDN and uses the resulting IPs in policy matching. This allows policies to be based on DNS names, which is useful for dynamic environments. Thus, it is a valid address object type for security policy rules.
- ✓
IP Netmask
Why this is correct
An IP Netmask address object, which defines a subnet (e.g., 192.168.1.0/24), is a fundamental type that can be directly referenced in security policy rules as a source or destination. It is one of the most common address object types used in policies to match traffic from or to a subnet. Therefore, it is a valid choice.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.