Courseiva
Managing Objects →mediumMultiple Choice

PCNSA Managing Objects Practice Question

An administrator needs to allow traffic from multiple subnets to a specific internal server. The subnets are all part of the same address group. Which object would simplify the security policy rule?

⚠ Common exam trap

Many exam-takers confuse address groups with service groups, thinking both are used for grouping, but service groups only apply to ports/protocols, not IP addresses or subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Address group

An address group allows the administrator to group multiple subnets into a single object, which can then be referenced in a security policy rule. This simplifies rule management by reducing the number of individual source address entries needed, making the policy easier to maintain and audit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tag

    Why it's wrong here

    Tags classify traffic by metadata and are applied per source or destination, so they cannot represent a group of subnets as a single reusable policy object. Tags suit dynamic, identity-based membership policies; here the subnets already exist as a static address group, which is the object the rule should reference.

  • ✗

    Schedule

    Why it's wrong here

    A schedule restricts when a rule is active, not which subnets it matches, so it leaves the multiple source addresses unresolved. Schedules are the right object when access must be limited to defined time windows, such as business hours, but this scenario concerns address grouping, not timing.

  • ✗

    Service group

    Why it's wrong here

    A service group bundles applications and ports, not IP addresses, so it cannot match the subnets in the address group. It is tempting because service groups do simplify rules, and they would be correct if the requirement involved multiple protocols or port ranges rather than multiple source subnets.

  • ✓

    Address group

    Why this is correct

    An address group bundles the multiple subnet objects into one named entity, so a single security policy rule references it rather than one rule per subnet. This satisfies the requirement to simplify the rule while covering all subnets.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.