PCNSA Managing Objects Practice Question
An administrator needs to allow traffic from multiple subnets to a specific internal server. The subnets are all part of the same address group. Which object would simplify the security policy rule?
⚠ Common exam trap
Many exam-takers confuse address groups with service groups, thinking both are used for grouping, but service groups only apply to ports/protocols, not IP addresses or subnets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Address group
An address group allows the administrator to group multiple subnets into a single object, which can then be referenced in a security policy rule. This simplifies rule management by reducing the number of individual source address entries needed, making the policy easier to maintain and audit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tag
Why it's wrong here
Tags classify traffic by metadata and are applied per source or destination, so they cannot represent a group of subnets as a single reusable policy object. Tags suit dynamic, identity-based membership policies; here the subnets already exist as a static address group, which is the object the rule should reference.
- ✗
Schedule
Why it's wrong here
A schedule restricts when a rule is active, not which subnets it matches, so it leaves the multiple source addresses unresolved. Schedules are the right object when access must be limited to defined time windows, such as business hours, but this scenario concerns address grouping, not timing.
- ✗
Service group
Why it's wrong here
A service group bundles applications and ports, not IP addresses, so it cannot match the subnets in the address group. It is tempting because service groups do simplify rules, and they would be correct if the requirement involved multiple protocols or port ranges rather than multiple source subnets.
- ✓
Address group
Why this is correct
An address group bundles the multiple subnet objects into one named entity, so a single security policy rule references it rather than one rule per subnet. This satisfies the requirement to simplify the rule while covering all subnets.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.