Courseiva
Managing Objects →easyMultiple Choice

PCNSA Managing Objects Practice Question

An administrator needs to block traffic from a specific internal IP address to the internet. Which object type should be used in the security policy source field?

⚠ Common exam trap

Watch out — candidates often confuse Address Groups with Address Objects, thinking they need a group for flexibility, but the question explicitly asks for the object type to use for a single IP, making the Address Object the direct and correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Address object

To block traffic from a specific internal IP address to the internet, you must identify that source IP in the security policy rule. An Address Object is the correct object type because it represents a single IP address or subnet and can be directly placed in the source field of a security policy rule to match traffic from that host. Tags, Address Groups, and Regions are not designed to represent a single IP address for source matching in this context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Address object

    Why this is correct

    An address object holds the specific internal IP as a host or range, so referencing it in the source field lets the policy match and block that traffic. It satisfies the requirement to identify a single internal IP precisely, unlike regions or application objects.

  • ✗

    Tag

    Why it's wrong here

    Tags classify traffic by metadata labels for dynamic grouping, not by a single literal IP; the source field needs an address object holding that exact host. Tags would be right for policy scoping across many ephemeral workloads sharing a label, not one fixed internal address.

  • ✗

    Address group

    Why it's wrong here

    An address group bundles multiple address objects for reuse; it holds no single host unless one is defined and added. It would be right when the policy must cover several internal addresses at once, not one specific IP.

  • ✗

    Region

    Why it's wrong here

    A Region object groups many external IP ranges by geography, so it cannot isolate one internal host. It would be the correct source when blocking or allowing traffic to an entire country or continent, not a single internal address.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.