Courseiva
Managing Objects →hardMultiple Select

PCNSA Managing Objects Practice Question

An administrator needs to create a dynamic address group that automatically includes all virtual machines in a VMware environment based on their tags. The firewall is integrated with VMware NSX-T. Which two actions must the administrator take to enable this dynamic grouping? (Choose two.)

⚠ Common exam trap

Many candidates confuse dynamic address groups with static groups or assuming that User-ID can map VM tags, when in fact NSX-T integration is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a dynamic address group with a filter that matches the VM tags.

To create a dynamic address group that automatically includes VMs based on VMware NSX-T tags, the administrator must first integrate the firewall with the NSX-T manager by configuring a service manager profile. Then, a dynamic address group must be created with a filter that matches the relevant tags. These two actions enable the firewall to query NSX-T for VM tags and populate the group dynamically. Static groups or subnet filters do not provide the required tag-based automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a dynamic address group with a filter that matches the VM tags.

    Why this is correct

    A dynamic address group uses a filter expression to match tags or other attributes. The administrator must define a filter that references the specific tags applied to the VMs, such as 'tag1' or 'env=prod'. This filter is evaluated by the firewall to dynamically populate the group with matching IP addresses. Without this step, the dynamic group would not know which VMs to include.

  • ✗

    Create a static address object for each VM and add them to a static address group.

    Why it's wrong here

    A static address group requires manual addition of address objects, which defeats the purpose of dynamic grouping. It would not automatically update as VMs are added or removed. The scenario explicitly requires automatic inclusion based on tags, so a static group is inappropriate. This action would not achieve the desired dynamic behavior.

  • ✗

    Configure a dynamic address group with a filter that matches the VM's IP subnet.

    Why it's wrong here

    Filtering by IP subnet would group VMs based on their network address, not their tags. The requirement is to group VMs based on tags, so a subnet filter would not meet the need. Additionally, VMs might share subnets with other non-target systems, leading to incorrect grouping. This approach does not leverage the tag-based integration with NSX-T.

  • ✓

    Register the firewall with the VMware NSX-T manager and configure the NSX-T service manager.

    Why this is correct

    To retrieve VM tags, the firewall must be integrated with the NSX-T manager. This involves configuring a service manager profile that specifies the NSX-T manager's address and credentials. Once registered, the firewall can query the NSX-T API for VM inventory and tags. This integration is essential for dynamic address groups to function with NSX-T tags.

  • ✗

    Enable User-ID and map VM tags to user attributes.

    Why it's wrong here

    User-ID is used for mapping users to IP addresses, not for integrating with VMware NSX-T tags. While User-ID can be used for dynamic groups based on user attributes, it does not retrieve VM tags from NSX-T. Enabling User-ID would not provide the necessary tag information for the dynamic address group. This action is irrelevant to the scenario.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.