PCNSA · domain
Managing Objects
The Managing Objects domain covers how PAN-OS stores and reuses address, service, application, and list objects that security policy references. Questions test object creation, naming, and reuse across zones and rules, plus External Dynamic Lists, VLAN interfaces, and deployment modes. Expect drag-and-drop ordering, matching, and multi-select items rather than long configuration scenarios.
Focused practice
Practice Managing Objects questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Managing Objects
Be able to create and reuse address, service, and application objects, attach EDLs to policy, and order VLAN interface steps correctly. The single most important thing: know which object type belongs in each policy field and that referenced objects cannot be freely changed.
Creating address, address group, service, and application objects in the Objects tab
Using External Dynamic Lists (EDLs) sourced from URLs or IP feeds in policy
Configuring Layer 3 VLAN interfaces with zones, virtual routers, and security zones
Mapping firewall deployment modes such as tap, virtual wire, Layer 2, and Layer 3
Watch out for
Common Managing Objects exam traps
- ▸Assuming an address object can be edited while referenced by a committed security rule; PAN-OS blocks or warns until references are removed.
- ▸Confusing EDL source types and refresh intervals, or expecting EDL contents to be editable locally on the firewall.
- ▸Forgetting that a VLAN interface needs a zone and virtual router assignment before policy can match traffic on it.
Question index
All Managing Objects questions (47)
Click any question to see the full explanation, or start a practice session above.
An administrator is creating a Dynamic Address Group (DAG) that should include all servers tagged with 'web' and 'prod'. The firewall is configured to use a VMware NSX-T service manager for tag registration. Which configuration is required to ensure the DAG is populated correctly?
Hard2Match each firewall deployment mode to its description.
Medium3An administrator needs to create a service object for a custom application that uses TCP port 8080 and UDP port 8080. What is the most efficient way to create this service object?
Easy4A company uses dynamic address groups based on tags. A virtual machine receives the tag "WebServer". After the VM is decommissioned, the tag is removed. What happens to the dynamic address group?
Hard5An administrator is creating address objects in PAN-OS and needs to ensure that they can be used in security policies to identify specific sources and destinations. Which two of the following are valid address object types that can be directly referenced in a security policy rule? (Choose two.)
Medium6An administrator is configuring a security policy rule that must allow access to a web server hosted at www.example.com. The web server's IP address changes frequently due to a content delivery network (CDN). The administrator wants the firewall to automatically update the IP address used in the rule without manual intervention. Which type of address object should be used?
Hard7A large enterprise uses dynamic address groups based on tags to manage firewall policies. The administrator notices that a specific address object is being incorrectly included in a dynamic address group that should only contain servers from a different region. What could be the reason?
Hard8An administrator needs to ensure that a security policy rule only allows traffic to a specific destination FQDN that resolves to multiple IP addresses, and the IP addresses change frequently. The administrator wants the firewall to automatically update the IP addresses without manual intervention. Which object type should the administrator use?
Medium9An administrator is configuring a Dynamic Address Group (DAG) to automatically include all servers that have the tag 'WebServer'. The DAG will be used in a security policy. Which two of the following statements are true regarding the configuration and behavior of this DAG? (Choose two.)
Hard10A security policy rule references a service object "HTTP" which is pre-defined. What is the default port for the HTTP service object?
Easy11An administrator is creating a new address object in PAN-OS and needs to ensure that the object can be used in security policies to match traffic from a specific subnet and also from a specific range of IP addresses within that subnet. Which two address object types should the administrator consider? (Choose two.)
Medium12An administrator needs to create a security rule that permits HTTP and HTTPS access to a web server cluster. The cluster members are defined as address objects named Web1, Web2, and Web3. The administrator wants to reference these three objects as a single entity in the security rule. Which object type should be created?
Medium13A company needs to block a list of known malicious domains that is updated daily by a threat intelligence vendor. Which Palo Alto Networks object should be used?
Medium14Which TWO statements about External Dynamic Lists (EDLs) are true?
Medium15An administrator needs to create a security policy rule that allows access to a web server with IP address 203.0.113.10, but the IP address may change in the future. The administrator wants to minimize manual updates to the policy. Which address object type should the administrator use?
Hard16A security administrator needs to create an address object for a single host with IP address 192.168.1.100. Which address type should the administrator choose?
Easy17A network administrator is configuring a security policy to allow SSH access to a server. The administrator wants to use a predefined service object for SSH. Which service object should be selected?
Easy18An administrator is creating service objects to define custom applications for a security policy. The administrator needs to create a service object for a custom TCP-based application that uses a single port, and another service object for an application that uses a range of UDP ports. Which two actions must the administrator take when defining these service objects? (Choose two.)
Medium19Which TWO types of address objects can be used in a security policy? (Choose two.)
Easy20A company has multiple branch offices that use overlapping private IP ranges (192.168.0.0/16). To avoid conflicts when these branches connect to the data center via IPsec, the administrator needs to translate branch source IPs to unique addresses. Which object type is best suited for this task?
Medium21Refer to the exhibit. An admin adds a new address object 'web-04' with IP 10.0.0.4 and applies it to a security policy that references the address group 'web-servers'. However, traffic to 10.0.0.4 is not allowed. What is the most likely cause?
Medium22An administrator wants to allow only specific applications (e.g., web-browsing, ssl) from the internal network to the internet. Which object type should be used in the security policy application field?
Medium23During a security audit, an administrator notices that a security policy rule uses an address group that includes an FQDN object. The FQDN resolves to multiple IP addresses that change frequently. What is the best practice for ensuring the firewall uses the current resolved IPs without manual intervention?
Hard24An administrator needs to block traffic from a specific internal IP address to the internet. Which object type should be used in the security policy source field?
Easy25An administrator is configuring a Dynamic Address Group (DAG) that uses tags to automatically include members. The administrator wants to ensure that the DAG is populated correctly. Which two actions are required to make a firewall register an IP address as a member of the DAG? (Choose two.)
Hard26An administrator wants to create a service object for TCP port 8080 and call it 'web-proxy'. Which properties must be specified?
Medium27An administrator creates a custom service object for TCP port 3389. What is the standard name for this service?
Medium28Which object type is used to group multiple service objects together for use in a security policy?
Easy29An administrator has created an address group that includes an FQDN address object. When the FQDN's IP address changes, how does the firewall update the group?
Medium30A network security administrator needs to create an address object that represents a range of IP addresses from 10.1.1.10 to 10.1.1.20. Which address object type should be used?
Medium31An administrator is configuring a security policy and needs to reference a set of external servers that are frequently updated by a third-party service. The servers' IP addresses change often, and the administrator wants the firewall to automatically update the list without manual intervention. Which type of object should the administrator use?
Easy32An administrator needs to create a dynamic address group that automatically includes all virtual machines in a VMware environment based on their tags. The firewall is integrated with VMware NSX-T. Which two actions must the administrator take to enable this dynamic grouping? (Choose two.)
Hard33An administrator is configuring a security policy and needs to allow access to a set of web servers that are defined by a dynamic address group. The dynamic address group uses the filter 'web-server' and tags are applied to the address objects. However, the administrator notices that the dynamic group is not populating with the expected members. Which action should the administrator take to troubleshoot this issue?
Medium34An administrator is configuring a security policy rule and needs to reference a service that uses both TCP port 80 and TCP port 443. The administrator wants to minimize the number of objects in the policy. What should the administrator create to achieve this?
Easy35An administrator needs to create an External Dynamic List (EDL) that contains a list of malicious IP addresses. The list is hosted on an internal web server at http://192.168.1.50/malicious.txt. The firewall must check for updates every hour. Which configuration is required?
Medium36An administrator needs to allow traffic from multiple subnets to a specific internal server. The subnets are all part of the same address group. Which object would simplify the security policy rule?
Medium37An administrator needs to create an object that represents a set of subnets belonging to the same department, but the subnets are not contiguous. The object will be used in a security policy rule and must be updated automatically when new subnets are added in IP address management (IPAM). Which type of address object should the administrator use?
Medium38An administrator is creating a security policy and needs to reference multiple service objects for different applications. The administrator wants to group these services into a single object that can be used in the policy. Which TWO of the following statements are true about service groups in PAN-OS? (Choose two.)
Medium39An administrator is creating an application filter to allow only specific applications while blocking others within a category. The administrator wants to ensure that the filter matches applications based on their risk level. Which attribute should the administrator use in the application filter?
Medium40A network security administrator is configuring a security policy to allow access to a set of web servers. The servers are located in a dynamic environment where new instances are added frequently. The administrator wants to ensure that the policy automatically includes new web servers without manual updates. The administrator has created a dynamic address group named 'WebServers-DAG' with the filter 'WebServer'. Which additional configuration is required to ensure that the dynamic address group is populated correctly?
Medium41A firewall administrator needs to allow traffic based on the application, not just port. Which type of object should be used in the security policy?
Hard42A network security administrator needs to create a service object that represents a custom application running on TCP port 8443 and UDP port 8443. The administrator wants to ensure that both protocols are matched by a single service object to simplify policy management. Which action should the administrator take?
Medium43An administrator creates a dynamic address group named 'prod-servers' configured to match any tag with the value 'production'. After tagging address objects with 'Production' (capital P), the group does not include them. What is the most likely cause?
Medium44Refer to the exhibit. An admin reviews the traffic log and sees that traffic from 192.168.1.100 to 10.0.0.50 is allowed by rule 'rule1'. The rule uses a service group 'web-services' which includes 'service-http' and 'service-https'. However, the admin intended to block HTTPS traffic. What is the misconfiguration?
Easy45An administrator is creating a security policy rule that must allow traffic from a group of users who are currently logged into the firewall via GlobalProtect. The administrator wants the rule to automatically include all users who are members of the 'Marketing' group in the directory service. Which type of object should be used in the Source User field of the security policy rule?
Medium46A security administrator is configuring an External Dynamic List (EDL) for IP addresses that will be used in a security policy to block malicious traffic. The EDL is hosted on an internal web server at https://edl.example.com/blocklist. The administrator wants to ensure that the firewall can retrieve the list and that it is updated every hour. Which configuration is required for the EDL to function correctly?
Hard47Drag and drop the steps to configure a VLAN interface on a Palo Alto Networks firewall into the correct order.
MediumOther domains
All PCNSA exam domains
Frequently asked questions
- What does the Managing Objects domain cover on the PCNSA exam?
- Be able to create and reuse address, service, and application objects, attach EDLs to policy, and order VLAN interface steps correctly. The single most important thing: know which object type belongs in each policy field and that referenced objects cannot be freely changed.
- How many questions are in this domain?
- This page lists all 47 Managing Objects questions in the PCNSA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Managing Objects questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.