Courseiva

CCNA Managing Objects Questions

47 questions · Managing Objects · All types, answers revealed

1
MCQhard

An administrator is creating a Dynamic Address Group (DAG) that should include all servers tagged with 'web' and 'prod'. The firewall is configured to use a VMware NSX-T service manager for tag registration. Which configuration is required to ensure the DAG is populated correctly?

A.Create an address group with type 'Dynamic' and a match filter that uses the tags 'web' and 'prod' with an 'and' operator.
B.Create a Dynamic Address Group and configure it to use the 'Any' filter, then rely on NSX-T to push the correct IP addresses.
C.Create a Dynamic Address Group with a filter that uses the tags 'web' or 'prod' with an 'or' operator.
D.Create an address group with type 'Static' and manually add the IP addresses of the servers.
AnswerA

A Dynamic Address Group uses a match filter to include members based on tags. To include only servers that have both 'web' and 'prod' tags, the filter must use the 'and' operator, such as 'web' and 'prod'. This ensures that only addresses with both tags are included. The DAG must also be configured to use the appropriate source, such as the NSX-T service manager, but the filter is the key to correct membership.

Why this answer

To create a Dynamic Address Group that includes only servers with both 'web' and 'prod' tags, the administrator must configure the DAG with a match filter that uses the 'and' operator between the tags. This ensures that only addresses that have both tags are included. The DAG must also be linked to the NSX-T service manager as the source of tags, but the filter logic is critical for correct membership.

Exam trap

The trap here is using an 'or' operator instead of 'and', which would include servers with either tag rather than both, leading to a broader group than intended.

2
Matchingmedium

Match each firewall deployment mode to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Passively monitors traffic without blocking

Transparent layer 2 deployment

Routable mode with IP addresses

Failover configuration with one standby unit

Why these pairings

The correct matches are: Layer 2 mode is a transparent bridge based on MAC addresses; Virtual Wire mode pairs interfaces as a wire; Layer 3 mode routes based on IP; Tap mode passively monitors. Common confusions involve swapping Layer 2 and Virtual Wire definitions, or confusing Tap with Layer 3.

3
MCQeasy

An administrator needs to create a service object for a custom application that uses TCP port 8080 and UDP port 8080. What is the most efficient way to create this service object?

A.Create a service object with protocol UDP and destination port 8080.
B.Create a single service object, add TCP and UDP protocols, and specify destination port 8080 for each.
C.Create two service objects: one for TCP port 8080 and one for UDP port 8080, then create a service group containing both.
D.Create a service object with protocol TCP and destination port 8080.
AnswerB

A single service object in PAN-OS can include multiple protocols. By selecting both TCP and UDP and specifying port 8080 for each, the administrator creates one object that matches both types of traffic. This is the most efficient method, reducing the number of objects and simplifying policy rules.

Why this answer

PAN-OS service objects can contain multiple protocol entries. To cover both TCP and UDP on port 8080, the administrator should create one service object and add two protocol entries: one for TCP with destination port 8080 and one for UDP with destination port 8080. This single object can then be referenced in security policies, providing a clean and efficient configuration.

Exam trap

The trap here is thinking that a service object can only have one protocol, but PAN-OS allows multiple protocols within a single service object.

4
MCQhard

A company uses dynamic address groups based on tags. A virtual machine receives the tag "WebServer". After the VM is decommissioned, the tag is removed. What happens to the dynamic address group?

A.The group automatically updates and removes the IP address.
B.The group retains the IP address until manually removed.
C.The group is deleted.
D.The group requires a commit to update.
AnswerA

Dynamic address groups resolve membership from tag criteria rather than static lists. When the WebServer tag is removed from the decommissioned VM, the firewall re-evaluates the filter and drops that IP automatically, requiring no manual edit.

Why this answer

Dynamic address groups update automatically based on tag membership. When the tag is removed from the VM, the VM's IP address is automatically removed from the group. No manual intervention or commit is required for the group to reflect the change, though a commit may be needed for policy enforcement.

5
Multi-Selectmedium

An administrator is creating address objects in PAN-OS and needs to ensure that they can be used in security policies to identify specific sources and destinations. Which two of the following are valid address object types that can be directly referenced in a security policy rule? (Choose two.)

Select 2 answers
A.Region
B.Service
C.Application Filter
D.FQDN
E.IP Netmask
AnswersD, E

An FQDN address object resolves a domain name to IP addresses and can be used in security policies. When referenced, the firewall resolves the FQDN and uses the resulting IPs in policy matching. This allows policies to be based on DNS names, which is useful for dynamic environments. Thus, it is a valid address object type for security policy rules.

Why this answer

IP Netmask and FQDN are both valid address object types that can be directly referenced in security policy rules. IP Netmask defines a subnet, and FQDN resolves a domain name to IPs. The other options are not address objects: Region is used for geographic targeting, while Service and Application Filter are used in other policy fields.

Thus, the correct choices are IP Netmask and FQDN.

Exam trap

The trap here is confusing other object types, such as Service or Region, with address objects that can be used in the source and destination fields of a security policy.

6
MCQhard

An administrator is configuring a security policy rule that must allow access to a web server hosted at www.example.com. The web server's IP address changes frequently due to a content delivery network (CDN). The administrator wants the firewall to automatically update the IP address used in the rule without manual intervention. Which type of address object should be used?

A.IP Range address object
B.FQDN address object
C.Dynamic address group
D.IP Netmask address object
AnswerB

An FQDN address object resolves a domain name to IP addresses and can be configured with a refresh interval. The firewall periodically queries DNS and updates the object with the current IP addresses. This allows security policies to automatically adapt to IP changes, such as those from a CDN, without manual updates. It is the appropriate choice for dynamically changing IP addresses tied to a domain name.

Why this answer

An FQDN address object is designed to resolve a domain name to IP addresses and can be configured to refresh at specified intervals. This enables the firewall to automatically update the object with the current IPs, ensuring security policies remain effective even when the web server's IP changes. For a CDN-hosted server, this provides the necessary automation without manual intervention.

Exam trap

The trap here is confusing dynamic address groups with FQDN objects; dynamic groups require external tag registration and do not perform DNS resolution.

7
MCQhard

A large enterprise uses dynamic address groups based on tags to manage firewall policies. The administrator notices that a specific address object is being incorrectly included in a dynamic address group that should only contain servers from a different region. What could be the reason?

A.The group is configured as static
B.The dynamic group uses 'match all' and the object lacks some tags
C.The administrator added the object directly to the group
D.The address object has multiple tags including the wrong one
AnswerD

Dynamic address groups match members purely by tag, so any address object carrying the group's tag is included automatically. If that object also holds the other region's tag, it joins both groups, explaining the incorrect inclusion described in the stem.

Why this answer

Dynamic address groups in Palo Alto Networks firewalls use tags to automatically include or exclude address objects. If an address object has multiple tags and one of them matches the tag criteria defined for the dynamic group, the object will be included even if it also has tags that would otherwise place it in a different region. This is the most likely cause of the incorrect inclusion.

Exam trap

The trap here is that candidates often assume dynamic groups use 'match all' by default or that tag conflicts are impossible, but the 'match any' operator is common and can cause objects with overlapping tags to be included in unintended groups.

How to eliminate wrong answers

Option A is wrong because a static group does not use tags for membership; objects are manually added or removed, so tag mismatches would not cause incorrect inclusion. Option B is wrong because if the group uses 'match all', the object would need to have all specified tags to be included; lacking some tags would exclude it, not cause incorrect inclusion. Option C is wrong because directly adding an object to a dynamic group is not possible; dynamic groups are populated solely by tag-based matching, not manual addition.

8
MCQmedium

An administrator needs to ensure that a security policy rule only allows traffic to a specific destination FQDN that resolves to multiple IP addresses, and the IP addresses change frequently. The administrator wants the firewall to automatically update the IP addresses without manual intervention. Which object type should the administrator use?

A.FQDN address object
B.Dynamic address group with a tag-based filter
C.Static address object with a single IP address
D.External Dynamic List (EDL) referencing a URL
AnswerA

An FQDN address object resolves the domain name to IP addresses and automatically updates the IP addresses when DNS changes. This meets the requirement of automatic updates without manual intervention. It is the correct choice for dynamic IP addresses associated with a domain name. The firewall periodically performs DNS resolution to keep the object current.

Why this answer

An FQDN address object is designed to resolve a domain name to its IP addresses and update them automatically as DNS records change. This provides dynamic IP address tracking without manual intervention. The other options either require manual updates or use different mechanisms that do not directly resolve FQDNs.

Thus, the FQDN address object is the correct solution for this scenario.

Exam trap

The trap here is confusing dynamic address groups with FQDN address objects, as both can handle dynamic IPs but rely on different mechanisms.

9
Multi-Selecthard

An administrator is configuring a Dynamic Address Group (DAG) to automatically include all servers that have the tag 'WebServer'. The DAG will be used in a security policy. Which two of the following statements are true regarding the configuration and behavior of this DAG? (Choose two.)

Select 2 answers
A.The DAG can be referenced in a security policy as a source or destination address.
B.The DAG requires the firewall to be connected to a User-ID agent to function.
C.The DAG can only contain IP addresses from a single subnet.
D.The DAG membership is updated automatically when the tags on address objects change.
E.The DAG filter must be written in a specific regular expression syntax.
AnswersA, D

Dynamic Address Groups are address objects themselves and can be used in security policies just like static address groups. They can be specified in the source or destination field of a rule, enabling dynamic enforcement based on group membership.

Why this answer

Dynamic Address Groups automatically update their membership based on tag changes, and they can be used in security policies as source or destination addresses. These two characteristics make DAGs powerful for dynamic environments where server roles or IPs change frequently.

Exam trap

The trap here is thinking that DAGs require a User-ID agent or use regex filters; actually, they rely on tag-based filters and do not need User-ID.

10
MCQeasy

A security policy rule references a service object "HTTP" which is pre-defined. What is the default port for the HTTP service object?

A.22
B.443
C.8080
D.80
AnswerD

The pre-defined HTTP service object maps to TCP port 80, the standard port for unencrypted web traffic. HTTPS uses 443 instead, so 80 is the correct default for the HTTP object referenced by the rule.

Why this answer

The HTTP service object in Palo Alto Networks firewalls is pre-defined with TCP port 80, as specified in RFC 7230. This default mapping allows the firewall to identify and apply security policies to standard unencrypted web traffic. Option D is correct because port 80 is the IANA-assigned default port for HTTP.

Exam trap

Palo Alto Networks often tests the distinction between HTTP (port 80) and HTTPS (port 443), and the trap here is that candidates may confuse HTTP with HTTPS or assume a common alternate port like 8080 is the default.

How to eliminate wrong answers

Option A is wrong because port 22 is the default port for SSH, not HTTP. Option B is wrong because port 443 is the default port for HTTPS (HTTP over SSL/TLS), not HTTP. Option C is wrong because port 8080 is an alternate port commonly used for HTTP proxies or web servers, but it is not the pre-defined default for the HTTP service object in Palo Alto Networks firewalls.

11
Multi-Selectmedium

An administrator is creating a new address object in PAN-OS and needs to ensure that the object can be used in security policies to match traffic from a specific subnet and also from a specific range of IP addresses within that subnet. Which two address object types should the administrator consider? (Choose two.)

Select 2 answers
A.IP Netmask
B.FQDN
C.IP Range
D.Dynamic Address Group
E.IP Wildcard Mask
AnswersA, C

IP Netmask is used to define a subnet by specifying the network address and subnet mask. It is ideal for matching an entire subnet, such as 192.168.1.0/24, and can be used in security policies to allow or deny traffic from that subnet. This addresses the subnet requirement.

Why this answer

To match a specific subnet, the administrator should use an IP Netmask object, which defines a network and mask. To match a specific range of IP addresses within that subnet, an IP Range object is appropriate, as it allows a start and end IP. Both types can be referenced in security policies.

The other types are either for domain names or dynamic membership, which do not fit the static requirements.

Exam trap

The trap here is assuming that a single object type can handle both a subnet and a range; in PAN-OS, these are distinct object types.

12
MCQmedium

An administrator needs to create a security rule that permits HTTP and HTTPS access to a web server cluster. The cluster members are defined as address objects named Web1, Web2, and Web3. The administrator wants to reference these three objects as a single entity in the security rule. Which object type should be created?

A.Service Group
B.Address Group
C.Dynamic Address Group
D.External Dynamic List
AnswerB

An address group is a container that references multiple address objects, allowing them to be referenced as a single entity in policy. Here, creating a static address group containing Web1, Web2, and Web3 lets the administrator use one group object in the security rule, simplifying management and ensuring all three servers are covered. This is the standard method to group address objects for policy use.

Why this answer

The correct answer is the address group, which is designed to group multiple address objects for use in policy. By creating a static address group containing Web1, Web2, and Web3, the administrator can reference a single object in the security rule, reducing administrative overhead and ensuring consistency. Other object types serve different purposes: service groups group services, dynamic address groups rely on tags, and EDLs import external lists.

Exam trap

The trap here is confusing address groups with service groups; both are containers, but they hold different types of objects and are used in different rule fields.

13
MCQmedium

A company needs to block a list of known malicious domains that is updated daily by a threat intelligence vendor. Which Palo Alto Networks object should be used?

A.External Dynamic List (EDL)
B.Custom URL Category
C.Address Group
D.Application Filter
AnswerA

An External Dynamic List imports the vendor's hosted domain feed directly, so the firewall refreshes entries automatically each day. This satisfies the daily-update constraint without manual edits, unlike static address or URL category objects that require administrator intervention.

Why this answer

An External Dynamic List (EDL) is the correct object because it allows Palo Alto Networks firewalls to import and automatically update a list of known malicious domains from an external threat intelligence vendor on a scheduled basis (e.g., every 5 minutes). This ensures the firewall dynamically blocks newly identified malicious domains without manual intervention, making it ideal for a daily-updated feed.

Exam trap

The trap here is that candidates often confuse Custom URL Categories with EDLs, assuming a manually updated list can suffice for dynamic feeds, but the exam emphasizes that EDLs are the only object designed for automated, external-sourced updates.

How to eliminate wrong answers

Option B is wrong because a Custom URL Category is a static, manually defined list of URLs or domains that does not support automatic updates from an external feed; it requires manual editing to reflect daily changes. Option C is wrong because an Address Group is used to group IP addresses or CIDR ranges, not domain names, and it cannot dynamically update from an external threat intelligence source. Option D is wrong because an Application Filter is used to identify traffic based on application characteristics (e.g., application ID, category, technology), not to block specific domains or URLs.

14
Multi-Selectmedium

Which TWO statements about External Dynamic Lists (EDLs) are true?

Select 2 answers
A.EDLs can be used in security policy source and destination fields.
B.EDLs have a fixed refresh interval that cannot be changed.
C.EDLs must be manually updated by an administrator.
D.EDLs support both IP addresses and URLs.
E.EDLs allow the administrator to add individual IPs directly via the GUI.
AnswersA, D

EDLs can be used as address objects in policies.

Why this answer

External Dynamic Lists (EDLs) can be used as source or destination objects in security policy rules. This allows the firewall to match traffic against a regularly updated list of IP addresses or URLs hosted externally, enabling dynamic threat intelligence integration without manual rule changes.

Exam trap

Palo Alto Networks often tests the misconception that EDLs require manual updates or have fixed refresh intervals, when in fact they are fully automated and configurable, and that EDLs can only be used for IP addresses, not URLs (though they support both).

15
MCQhard

An administrator needs to create a security policy rule that allows access to a web server with IP address 203.0.113.10, but the IP address may change in the future. The administrator wants to minimize manual updates to the policy. Which address object type should the administrator use?

A.Dynamic address group
B.External Dynamic List (EDL)
C.Static address object
D.FQDN address object
AnswerD

An FQDN address object resolves a domain name to IP addresses and automatically updates when DNS changes. If the web server's IP changes, the administrator only needs to update the DNS record, and the firewall will resolve the new IP. This minimizes manual updates to the policy. It is the correct choice for minimizing manual updates.

Why this answer

An FQDN address object automatically resolves a domain name to IP addresses and updates when DNS changes. This means if the web server's IP changes, the administrator only needs to update the DNS record, and the firewall will automatically use the new IP. This minimizes manual updates to the security policy.

Static objects, dynamic address groups, and EDLs require more manual intervention or additional infrastructure. Therefore, the FQDN address object is the best choice.

Exam trap

The trap here is assuming that dynamic address groups or EDLs automatically track an FQDN's IP changes, but they require external tagging or list maintenance.

16
MCQeasy

A security administrator needs to create an address object for a single host with IP address 192.168.1.100. Which address type should the administrator choose?

A.FQDN
B.IP Netmask
C.IP Wildcard Mask
D.IP Range
AnswerB

IP Netmask defines a host by pairing an address with a subnet mask, so entering 192.168.1.100 with mask 255.255.255.255 (/32) isolates that single host. This satisfies the stem's requirement for one host, whereas IP Range and FQDN cannot express a lone address as precisely.

Why this answer

For a single host with IP address 192.168.1.100, the IP Netmask type is correct because it allows you to define a host by specifying the IP address with a /32 netmask (255.255.255.255). This is the standard method in Palo Alto Networks firewalls to represent a single host, ensuring the device treats it as an exact match for traffic policy and security rules.

Exam trap

The trap here is that candidates familiar with Cisco ACLs might choose IP Wildcard Mask (Option C) because they associate wildcard masks with host matching, but Palo Alto Networks uses IP Netmask as the standard and more straightforward method for defining a single host.

How to eliminate wrong answers

Option A (FQDN) is wrong because it is used for domain names that resolve to one or more IP addresses via DNS, not for a static IP address. Option C (IP Wildcard Mask) is wrong because it uses a wildcard mask to match a range of IPs (like Cisco ACLs), but it is not the intended type for a single host in Palo Alto Networks; it would require a mask of 0.0.0.0 to match a single host, which is less intuitive and not the recommended approach. Option D (IP Range) is wrong because it defines a contiguous range of IP addresses (e.g., 192.168.1.100-192.168.1.110), which is unnecessary and less precise for a single host.

17
MCQeasy

A network administrator is configuring a security policy to allow SSH access to a server. The administrator wants to use a predefined service object for SSH. Which service object should be selected?

A.ssh-tcp
B.ssh
C.service-ssh
D.tcp-22
AnswerB

PAN-OS includes a predefined service object named 'ssh' that defines TCP port 22. This object is available by default and can be used directly in security policies. Selecting 'ssh' ensures the correct port and protocol are applied without manual configuration, reducing the risk of errors. This is the standard predefined service for SSH.

Why this answer

The predefined service object 'ssh' is the correct choice because it is already defined in PAN-OS with the appropriate protocol (TCP) and port (22). Using predefined services simplifies policy creation and ensures accuracy. The other options are either non-existent or custom names that would require manual creation, which does not meet the requirement of using a predefined object.

Exam trap

The trap here is assuming that predefined service names always include the protocol or port number, leading to guesses like 'ssh-tcp' or 'tcp-22'.

18
Multi-Selectmedium

An administrator is creating service objects to define custom applications for a security policy. The administrator needs to create a service object for a custom TCP-based application that uses a single port, and another service object for an application that uses a range of UDP ports. Which two actions must the administrator take when defining these service objects? (Choose two.)

Select 2 answers
A.Specify the protocol as TCP for the single-port service.
B.Specify the protocol as UDP for the port-range service.
C.Set the destination port to 0 for the single-port service.
D.Use a dynamic address group to define the service.
E.Enable the 'Override' option to allow port ranges.
AnswersA, B

When creating a service object for a TCP-based application, the protocol must be set to TCP. This ensures the firewall matches TCP traffic on the specified port. Without specifying the protocol, the service object would not accurately define the application, and the security policy might not match correctly. This is a required step for defining a TCP service object.

Why this answer

To define service objects for custom applications, the protocol must be correctly set (TCP or UDP) and the appropriate port or port range specified. For a TCP single-port service, set protocol to TCP and specify the port. For a UDP port-range service, set protocol to UDP and define the range.

These two actions are essential for accurate traffic matching.

Exam trap

The trap here is assuming that service objects can be defined without specifying the protocol or that port 0 is valid.

19
Multi-Selecteasy

Which TWO types of address objects can be used in a security policy? (Choose two.)

Select 2 answers
A.Application
B.Tag
C.IP Netmask
D.IP Range
E.Service
AnswersC, D

An IP Netmask address object defines a subnet range, such as 10.0.0.0/24, and is a valid match criterion in Palo Alto Networks security policy source and destination fields, satisfying the question's requirement for usable address object types.

Why this answer

In a Palo Alto Networks security policy, address objects are used to match the source and destination fields, and the valid address object types include IP Netmask (a subnet defined by an IP address and a subnet mask, e.g., 192.168.1.0/24) and IP Range (a contiguous span of addresses defined by a start and end IP, e.g., 192.168.1.10-192.168.1.20), so options C and D are correct. These two types are explicitly selectable as address objects when building source or destination matching criteria in the policy rule. Option A (Application) is incorrect because applications are matched via the Application field using application objects or application filters, not address objects.

Option B (Tag) is incorrect because tags are metadata labels used for grouping and filtering objects or rules, not an address object type usable in the source/destination address fields. Option E (Service) is incorrect because services (TCP/UDP port and protocol definitions) are matched in the Service/Application field, not as address objects.

Exam trap

Palo Alto Networks often tests the distinction between address objects and other policy elements like services or applications, so the trap here is that candidates mistakenly think Application or Service can serve as address objects because they are also used in security rules, but they occupy different match fields.

20
MCQmedium

A company has multiple branch offices that use overlapping private IP ranges (192.168.0.0/16). To avoid conflicts when these branches connect to the data center via IPsec, the administrator needs to translate branch source IPs to unique addresses. Which object type is best suited for this task?

A.NAT address pool
B.External dynamic list
C.Service group
D.IPsec Crypto profile
AnswerA

A NAT address pool supplies unique translated source addresses for outbound IPsec traffic, resolving overlapping 192.168.0.0/16 ranges between branches. It maps each branch's private source IPs to distinct pool addresses, preventing conflicts when connecting to the data centre.

Why this answer

A NAT address pool is the correct object type because it allows the administrator to translate overlapping private IP addresses (192.168.0.0/16) from multiple branch offices into unique, non-overlapping IP addresses before sending traffic over the IPsec tunnel. This prevents routing conflicts at the data center by ensuring each branch's source IPs are mapped to distinct addresses from a defined pool, a process known as source NAT (SNAT) or IP address translation.

Exam trap

The trap here is that candidates may confuse NAT address pools with IPsec Crypto profiles, thinking that VPN configuration alone resolves IP overlap, when in fact IPsec only encrypts traffic and does not perform address translation to resolve overlapping subnets.

How to eliminate wrong answers

Option B (External dynamic list) is wrong because it is used to dynamically import and manage IP addresses or URLs from an external source (e.g., threat intelligence feeds) for security policy matching, not for performing NAT translations. Option C (Service group) is wrong because it is a logical grouping of services (protocols and ports) used in security policy rules to simplify rule creation, not for IP address translation. Option D (IPsec Crypto profile) is wrong because it defines the IKE and IPsec parameters (e.g., encryption algorithms, authentication methods, DH groups) for securing VPN tunnels, not for translating overlapping IP addresses.

21
MCQmedium

Refer to the exhibit. An admin adds a new address object 'web-04' with IP 10.0.0.4 and applies it to a security policy that references the address group 'web-servers'. However, traffic to 10.0.0.4 is not allowed. What is the most likely cause?

A.The admin forgot to add 'web-04' to the address group
B.The address object 'web-04' has the wrong IP
C.The address group is dynamic and did not update
D.The security policy is set to deny
AnswerA

Security policies match address group members, not objects merely created in the address book. Because 'web-04' was never added to 'web-servers', the policy never evaluates 10.0.0.4, so its traffic is denied despite the object existing.

Why this answer

The address object 'web-04' was created but not added to the address group 'web-servers'. In Palo Alto Networks firewalls, security policies reference address groups, not individual objects. Even if the object exists, the policy will not match traffic destined to 10.0.0.4 unless the object is a member of the referenced group.

This is the most common cause of such a failure.

Exam trap

Palo Alto Networks often tests the distinction between creating an object and applying it to a group; the trap here is that candidates assume creating the object and referencing the group in the policy is sufficient, forgetting that the object must be a member of the group for the policy to match.

How to eliminate wrong answers

Option B is wrong because the question states the IP is 10.0.0.4 and the admin applied it to the policy; if the IP were wrong, the traffic would still not match, but the most likely cause is the group membership issue, not an IP typo. Option C is wrong because dynamic address groups update automatically based on tags or filters; if the group were dynamic, adding the object with the correct tag would cause it to be included, but the admin would need to ensure the tag matches, and the question does not indicate a dynamic group failure. Option D is wrong because the question states the policy references the address group 'web-servers' and traffic is not allowed; if the policy were set to deny, it would explicitly block traffic, but the most likely cause is the missing group membership, not a deny action.

22
MCQmedium

An administrator wants to allow only specific applications (e.g., web-browsing, ssl) from the internal network to the internet. Which object type should be used in the security policy application field?

A.Application object
B.Application filter
C.Application group
D.Service object
AnswerA

Application objects identify traffic by application signatures rather than port or protocol, so the policy can permit web-browsing and ssl specifically. This satisfies the requirement to allow only those named applications from internal to internet.

Why this answer

Application object, because in Palo Alto Networks security policies, the application field uses predefined or custom application objects to identify traffic based on the application identity, not just port/protocol. This allows the administrator to permit specific applications like web-browsing (HTTP/HTTPS) and SSL while blocking others, even if they use the same ports. Application objects leverage App-ID technology to inspect traffic beyond Layer 4, ensuring only allowed applications pass.

Exam trap

The trap here is that candidates often confuse service objects (Layer 4) with application objects (Layer 7), assuming that specifying a port/protocol is sufficient to control applications, but the PCNSA exam emphasizes that application-based policies require App-ID objects for granular control.

How to eliminate wrong answers

Option B is wrong because an Application filter is used to dynamically group applications based on criteria like category or technology, but it cannot be directly placed in the security policy application field; it is used in other contexts like QoS or policy optimization. Option C is wrong because an Application group is a static collection of application objects, but the question asks for the object type to allow specific applications individually, not a group; using a group could inadvertently permit unintended applications within the group. Option D is wrong because a Service object defines Layer 4 protocols and ports (e.g., TCP/443 for HTTPS), but it cannot enforce application-level control; for example, it would allow any traffic on port 443, not just SSL, failing to meet the requirement of allowing only specific applications.

23
MCQhard

During a security audit, an administrator notices that a security policy rule uses an address group that includes an FQDN object. The FQDN resolves to multiple IP addresses that change frequently. What is the best practice for ensuring the firewall uses the current resolved IPs without manual intervention?

A.Use a region object instead
B.Create a dynamic address group with a tag-based filter
C.Use an FQDN object in the address group; the firewall resolves it automatically
D.Manually add all possible IP addresses to an address group
AnswerC

FQDN objects automatically resolve and update IPs.

Why this answer

Palo Alto Networks firewalls automatically resolve FQDN objects to their current IP addresses at runtime, without requiring manual updates. When an FQDN object is used in an address group, the firewall performs DNS resolution each time the policy is evaluated, ensuring that the latest IP addresses are used even if they change frequently.

Exam trap

The trap here is that candidates may think FQDN objects require manual IP updates or that dynamic address groups can perform DNS resolution, but in reality, only FQDN objects provide automatic, runtime DNS resolution without manual intervention.

How to eliminate wrong answers

Option A is wrong because a region object is based on geographic location (e.g., country or continent) and cannot represent a dynamic set of IP addresses resolved from an FQDN. Option B is wrong because a dynamic address group with a tag-based filter is used to group objects by tags, not to automatically resolve FQDNs to IPs; it does not handle DNS resolution. Option D is wrong because manually adding all possible IP addresses is impractical and error-prone when IPs change frequently, and it defeats the purpose of automation and dynamic resolution.

24
MCQeasy

An administrator needs to block traffic from a specific internal IP address to the internet. Which object type should be used in the security policy source field?

A.Address object
B.Tag
C.Address group
D.Region
AnswerA

An address object holds the specific internal IP as a host or range, so referencing it in the source field lets the policy match and block that traffic. It satisfies the requirement to identify a single internal IP precisely, unlike regions or application objects.

Why this answer

To block traffic from a specific internal IP address to the internet, you must identify that source IP in the security policy rule. An Address Object is the correct object type because it represents a single IP address or subnet and can be directly placed in the source field of a security policy rule to match traffic from that host. Tags, Address Groups, and Regions are not designed to represent a single IP address for source matching in this context.

Exam trap

The trap here is that candidates may confuse Address Groups with Address Objects, thinking they need a group for flexibility, but the question explicitly asks for the object type to use for a single IP, making the Address Object the direct and correct answer.

How to eliminate wrong answers

Option B (Tag) is wrong because Tags are metadata labels used for policy identification, grouping, or dynamic filtering, not for matching source IP addresses in a security rule. Option C (Address Group) is wrong because while an Address Group can contain Address Objects, using a group for a single IP is unnecessary and adds complexity; the question asks for the object type to use, and the most direct and correct choice is the Address Object itself. Option D (Region) is wrong because Region objects define geographic locations based on IP ranges, not a specific internal IP address, and are typically used in destination or source fields for geo-blocking, not for blocking a single host.

25
Multi-Selecthard

An administrator is configuring a Dynamic Address Group (DAG) that uses tags to automatically include members. The administrator wants to ensure that the DAG is populated correctly. Which two actions are required to make a firewall register an IP address as a member of the DAG? (Choose two.)

Select 2 answers
A.The firewall must receive the tag information via an external source, such as a User-ID agent or a syslog listener.
B.The administrator must enable the 'Dynamic Group' option in the security policy rule.
C.The administrator must manually add each IP address as a static member of the DAG.
D.The DAG filter must reference the tags that are registered for the IP addresses.
E.The firewall must be configured to resolve the IP addresses to hostnames via DNS.
AnswersA, D

Dynamic Address Groups rely on tags that are registered with the firewall. These tags can be learned through various methods, including User-ID agents, syslog listeners, or the XML API. Without a source providing the tag-to-IP mapping, the firewall cannot know which IPs belong to the group. Therefore, receiving tag information from an external source is essential for the DAG to be populated.

Why this answer

Dynamic Address Groups are populated based on tags that are registered with the firewall. The two essential actions are: the firewall must receive tag information from an external source (like User-ID agent or syslog), and the DAG filter must reference those tags. Without both, the group will not be populated.

Manual addition or DNS resolution are not part of the DAG mechanism.

Exam trap

The trap here is thinking that DAGs require manual IP entry or that they use DNS, when they actually rely on external tag registration and filter matching.

26
MCQmedium

An administrator wants to create a service object for TCP port 8080 and call it 'web-proxy'. Which properties must be specified?

A.Destination port
B.Both destination port and protocol
C.Source port
D.Protocol
AnswerB

A service object is defined by its protocol and destination port; the name 'web-proxy' is just a label. Specifying TCP and port 8080 lets the firewall match that traffic, satisfying the requirement to create the object.

Why this answer

In Palo Alto Networks firewalls, a service object defines a specific application protocol and port combination for traffic classification and policy enforcement. For TCP port 8080, both the protocol (TCP) and the destination port (8080) must be specified because the firewall requires the protocol to differentiate between TCP, UDP, or other IP protocols, and the destination port to match the traffic. Option B is correct because without both, the service object would be incomplete and could not be used in security rules.

Exam trap

The trap here is that candidates often assume only the destination port is needed, forgetting that the protocol is mandatory to uniquely identify the service, as the same port number can be used by different protocols (e.g., TCP vs. UDP).

How to eliminate wrong answers

Option A is wrong because specifying only the destination port without the protocol would leave the service object ambiguous, as the firewall cannot determine whether the traffic uses TCP, UDP, or another protocol. Option C is wrong because source ports are not used in service object definitions; service objects are based on destination ports and protocols, as source ports are typically ephemeral and not relevant for service identification. Option D is wrong because specifying only the protocol without a destination port would create a generic service that matches all traffic of that protocol, which is not the intended behavior for a specific TCP port 8080 service.

27
MCQmedium

An administrator creates a custom service object for TCP port 3389. What is the standard name for this service?

A.FTP
B.RDP
C.SSH
D.Telnet
AnswerB

TCP port 3389 is the registered port for Remote Desktop Protocol, so Palo Alto Networks recognises the custom service object by its standard name RDP. Naming it correctly ensures the security policy matches Remote Desktop traffic rather than relying on an ambiguous custom label.

Why this answer

TCP port 3389 is the default port used by Remote Desktop Protocol (RDP), which is a Microsoft proprietary protocol that enables remote graphical desktop access to Windows systems. The administrator creating a custom service object for this port is standardizing the service as RDP, as defined in the PCNSA curriculum for managing objects.

Exam trap

The trap here is that candidates may confuse RDP with other remote access protocols like SSH or Telnet, but the specific port 3389 is exclusively associated with RDP in standard networking practice.

How to eliminate wrong answers

Option A is wrong because FTP (File Transfer Protocol) uses TCP ports 20 and 21, not 3389. Option C is wrong because SSH (Secure Shell) uses TCP port 22, not 3389. Option D is wrong because Telnet uses TCP port 23, not 3389.

28
MCQeasy

Which object type is used to group multiple service objects together for use in a security policy?

A.Schedule
B.Tag
C.Service group
D.Address group
AnswerC

A service group holds multiple service objects, letting a single policy rule reference them collectively. This matches the stem's need to group services for use in a security policy, unlike individual service objects or application filters.

Why this answer

A service group is the correct object type because it allows you to combine multiple service objects (e.g., TCP/UDP port numbers) into a single logical group. This group can then be referenced directly in a security policy rule, simplifying rule creation and maintenance by reducing the number of individual service entries needed.

Exam trap

The trap here is that candidates often confuse 'service group' with 'address group' because both are grouping constructs, but they serve entirely different purposes — one for ports/protocols and one for IP addresses — and the exam expects you to know which object type applies to which policy element.

How to eliminate wrong answers

Option A is wrong because a Schedule object is used to define time-based access control (e.g., business hours), not to group service objects. Option B is wrong because a Tag is a metadata label for filtering or organizing objects in the firewall GUI, not a container for service definitions. Option D is wrong because an Address group is used to group IP addresses or FQDNs, not services; it is the correct grouping mechanism for network objects, not service objects.

29
MCQmedium

An administrator has created an address group that includes an FQDN address object. When the FQDN's IP address changes, how does the firewall update the group?

A.The administrator must manually update the address object's IP address.
B.Only if the address group is dynamic will the update occur automatically.
C.FQDN objects cannot be included in address groups.
D.The firewall automatically resolves the FQDN at commit and updates the group accordingly.
AnswerD

FQDN address objects are resolved through DNS at commit time, and the resulting IP addresses populate any group referencing them. When the FQDN's records change, the next commit re-resolves and refreshes the group membership automatically, requiring no manual edit.

Why this answer

Palo Alto Networks firewalls automatically resolve FQDNs at commit time. When an FQDN address object is included in an address group, the firewall performs a DNS resolution during the commit process and updates the group with the current IP address(es). This ensures that the group reflects the latest IP mapping without requiring manual intervention.

Exam trap

The trap here is that candidates may think FQDNs require manual updates or that only dynamic groups support automatic resolution, but Palo Alto firewalls resolve FQDNs at commit for any group type.

How to eliminate wrong answers

Option A is wrong because the firewall automatically resolves the FQDN at commit, so manual updates are unnecessary. Option B is wrong because the automatic update occurs regardless of whether the address group is static or dynamic; the FQDN resolution happens at commit for any group containing an FQDN object. Option C is wrong because FQDN objects can indeed be included in address groups; they are a supported object type in Palo Alto Networks address groups.

30
MCQmedium

A network security administrator needs to create an address object that represents a range of IP addresses from 10.1.1.10 to 10.1.1.20. Which address object type should be used?

A.FQDN
B.Dynamic
C.IP Netmask
D.IP Range
AnswerD

An IP Range address object allows the administrator to specify a starting and ending IP address, such as 10.1.1.10-10.1.1.20. This is the correct choice because it exactly represents the contiguous range needed, and PAN-OS supports this type for both IPv4 and IPv6. Using an IP Range object simplifies policy management by treating the entire range as a single entity.

Why this answer

The requirement is to represent a specific range of IP addresses from 10.1.1.10 to 10.1.1.20. PAN-OS provides an address object type called IP Range that allows defining a start and end IP address. This type is designed exactly for such scenarios, enabling efficient policy management without needing to list each address individually or use a subnet that might include unwanted addresses.

Exam trap

The trap here is assuming that an IP Netmask object can represent any contiguous range, but it can only represent subnets that align to network boundaries.

31
MCQeasy

An administrator is configuring a security policy and needs to reference a set of external servers that are frequently updated by a third-party service. The servers' IP addresses change often, and the administrator wants the firewall to automatically update the list without manual intervention. Which type of object should the administrator use?

A.FQDN address object
B.External Dynamic List (EDL)
C.Static address group
D.Dynamic address group
AnswerB

An External Dynamic List (EDL) allows the firewall to periodically fetch a list of IP addresses, URLs, or domains from an external web server. The firewall automatically updates the list at configured intervals, so the administrator does not need to manually update the object when the third-party service changes the IPs.

Why this answer

An External Dynamic List is designed to automatically retrieve and update lists of IP addresses, URLs, or domains from an external server. By configuring an EDL, the firewall periodically pulls the list and uses it in policy, ensuring that changes made by the third-party service are reflected without manual intervention. This is the most efficient and appropriate solution for dynamically changing IP lists.

Exam trap

The trap here is confusing dynamic address groups with External Dynamic Lists; dynamic address groups require tags and do not directly consume external IP lists without an EDL.

32
Multi-Selecthard

An administrator needs to create a dynamic address group that automatically includes all virtual machines in a VMware environment based on their tags. The firewall is integrated with VMware NSX-T. Which two actions must the administrator take to enable this dynamic grouping? (Choose two.)

Select 2 answers
A.Configure a dynamic address group with a filter that matches the VM tags.
B.Create a static address object for each VM and add them to a static address group.
C.Configure a dynamic address group with a filter that matches the VM's IP subnet.
D.Register the firewall with the VMware NSX-T manager and configure the NSX-T service manager.
E.Enable User-ID and map VM tags to user attributes.
AnswersA, D

A dynamic address group uses a filter expression to match tags or other attributes. The administrator must define a filter that references the specific tags applied to the VMs, such as 'tag1' or 'env=prod'. This filter is evaluated by the firewall to dynamically populate the group with matching IP addresses. Without this step, the dynamic group would not know which VMs to include.

Why this answer

To create a dynamic address group that automatically includes VMs based on VMware NSX-T tags, the administrator must first integrate the firewall with the NSX-T manager by configuring a service manager profile. Then, a dynamic address group must be created with a filter that matches the relevant tags. These two actions enable the firewall to query NSX-T for VM tags and populate the group dynamically.

Static groups or subnet filters do not provide the required tag-based automation.

Exam trap

The trap here is confusing dynamic address groups with static groups or assuming that User-ID can map VM tags, when in fact NSX-T integration is required.

33
MCQmedium

An administrator is configuring a security policy and needs to allow access to a set of web servers that are defined by a dynamic address group. The dynamic address group uses the filter 'web-server' and tags are applied to the address objects. However, the administrator notices that the dynamic group is not populating with the expected members. Which action should the administrator take to troubleshoot this issue?

A.Restart the management plane to refresh the dynamic address group membership.
B.Verify that the tag 'web-server' is registered on the firewall and applied to the correct address objects.
C.Check that the firewall has a valid license for dynamic address groups.
D.Ensure that the dynamic address group is referenced in a security policy with the correct source and destination zones.
AnswerB

Dynamic address groups rely on tags to populate their members. The filter 'web-server' will match address objects that have the tag 'web-server'. If the tag is not registered or not applied to the address objects, the group will remain empty. Checking tag registration and application is the first troubleshooting step.

Why this answer

Dynamic address groups populate based on tags applied to address objects. The filter must reference existing tags that are applied correctly. If the group is empty, the most likely cause is that the tag is missing or not applied to the intended address objects.

Verifying tag registration and application directly addresses the root cause.

Exam trap

The trap here is focusing on policy or licensing when the issue is simply that the tag is not properly applied to the address objects.

34
MCQeasy

An administrator is configuring a security policy rule and needs to reference a service that uses both TCP port 80 and TCP port 443. The administrator wants to minimize the number of objects in the policy. What should the administrator create to achieve this?

A.An application group containing web-browsing and ssl.
B.A custom service object with both ports defined.
C.A service group containing service-http and service-https.
D.An address group containing the server's IP address.
AnswerC

A service group allows bundling multiple service objects into a single reference. By creating a service group that includes service-http (TCP/80) and service-https (TCP/443), the administrator can use one object in the security policy. This reduces the number of objects and simplifies management. It is the most efficient way to represent multiple services in a single policy rule.

Why this answer

A service group is designed to bundle multiple service objects for use in security policies. By creating a service group that contains service-http and service-https, the administrator can reference both ports with a single object. This minimizes the number of objects and simplifies policy management.

Custom service objects cannot contain multiple ports, and address or application groups serve different purposes.

Exam trap

The trap here is thinking a single custom service object can define multiple ports, but in PAN-OS each service object only supports one protocol and one port range.

35
MCQmedium

An administrator needs to create an External Dynamic List (EDL) that contains a list of malicious IP addresses. The list is hosted on an internal web server at http://192.168.1.50/malicious.txt. The firewall must check for updates every hour. Which configuration is required?

A.Create an EDL object with type 'IP List', source URL 'http://192.168.1.50/malicious.txt', and set the check interval to 60 minutes.
B.Create an EDL object with type 'IP List', source URL 'https://192.168.1.50/malicious.txt', and set the check interval to 60 minutes.
C.Create an EDL object with type 'Domain List', source URL 'http://192.168.1.50/malicious.txt', and set the check interval to 60 minutes.
D.Create an EDL object with type 'IP List', source URL 'http://192.168.1.50/malicious.txt', and set the check interval to 5 minutes.
AnswerA

An External Dynamic List of type 'IP List' is used for IP addresses. The source URL points to the hosted file, and the check interval determines how often the firewall retrieves updates. Setting it to 60 minutes meets the hourly requirement. This configuration will automatically update the list and can be referenced in security policies.

Why this answer

To create an External Dynamic List for malicious IP addresses hosted on an internal web server via HTTP, the administrator must configure an EDL of type 'IP List' with the correct source URL and set the check interval to 60 minutes. This ensures the firewall retrieves the list hourly, as required. The EDL can then be used in security policies to block traffic from those IP addresses.

Exam trap

The trap here is selecting the wrong EDL type or using HTTPS when the source is HTTP, which would prevent successful retrieval of the list.

36
MCQmedium

An administrator needs to allow traffic from multiple subnets to a specific internal server. The subnets are all part of the same address group. Which object would simplify the security policy rule?

A.Tag
B.Schedule
C.Service group
D.Address group
AnswerD

An address group bundles the multiple subnet objects into one named entity, so a single security policy rule references it rather than one rule per subnet. This satisfies the requirement to simplify the rule while covering all subnets.

Why this answer

An address group allows the administrator to group multiple subnets into a single object, which can then be referenced in a security policy rule. This simplifies rule management by reducing the number of individual source address entries needed, making the policy easier to maintain and audit.

Exam trap

The trap here is that candidates may confuse address groups with service groups, thinking both are used for grouping, but service groups only apply to ports/protocols, not IP addresses or subnets.

How to eliminate wrong answers

Option A is wrong because tags are used for policy rule categorization and filtering in the management interface, not for grouping IP addresses or subnets. Option B is wrong because schedules define time-based access windows and have no relation to grouping subnets for source matching. Option C is wrong because service groups are used to combine multiple protocols or ports (e.g., TCP/80 and TCP/443) into a single object, not to group IP addresses or subnets.

37
MCQmedium

An administrator needs to create an object that represents a set of subnets belonging to the same department, but the subnets are not contiguous. The object will be used in a security policy rule and must be updated automatically when new subnets are added in IP address management (IPAM). Which type of address object should the administrator use?

A.IP Netmask address object
B.Dynamic address group
C.IP Range address object
D.FQDN address object
AnswerB

A dynamic address group uses tags to automatically include address objects that match a filter. When new subnets are registered in IPAM and tagged appropriately, they can be dynamically added to the group. This meets the requirement for a non-contiguous set of subnets and automatic updates, making it the most efficient and scalable solution.

Why this answer

A dynamic address group is designed to automatically include address objects based on tags, which can be updated by external systems like IPAM. This allows the group to reflect changes without manual intervention. For non-contiguous subnets that need automatic updates, this object type provides the necessary flexibility and integration, unlike static address objects that require manual maintenance.

Exam trap

The trap here is assuming that a static address group or IP range can represent multiple non-contiguous subnets and be automatically updated.

38
Multi-Selectmedium

An administrator is creating a security policy and needs to reference multiple service objects for different applications. The administrator wants to group these services into a single object that can be used in the policy. Which TWO of the following statements are true about service groups in PAN-OS? (Choose two.)

Select 2 answers
A.A service group can be used in the Source Address field of a security policy.
B.A service group can contain other service groups, allowing for hierarchical grouping.
C.A service group can contain applications, allowing for application-based filtering.
D.A service group can contain both predefined and custom service objects.
E.A service group can contain address objects to simplify policy creation.
AnswersB, D

PAN-OS supports nested service groups, meaning a service group can include other service groups as members. This enables hierarchical organization of services, which can be useful for large environments. However, excessive nesting can impact performance and manageability, so it should be used judiciously. This is a valid and supported configuration.

Why this answer

The two true statements are that a service group can contain both predefined and custom service objects, and that it can contain other service groups (nested groups). These capabilities provide flexibility in grouping services for policy use. The other options are false because service groups are restricted to service objects and cannot contain address objects or applications, nor can they be used in address fields.

Exam trap

The trap here is assuming that any group object can contain any type of object; in PAN-OS, groups are type-specific and cannot mix object types.

39
MCQmedium

An administrator is creating an application filter to allow only specific applications while blocking others within a category. The administrator wants to ensure that the filter matches applications based on their risk level. Which attribute should the administrator use in the application filter?

A.Subcategory
B.Category
C.Technology
D.Risk
AnswerD

Risk is an attribute that indicates the security risk level of an application, ranging from 1 to 5. By using Risk in an application filter, the administrator can include or exclude applications based on their risk rating. This directly satisfies the requirement to match applications by risk level. It allows policies to, for example, allow only low-risk applications while blocking high-risk ones.

Why this answer

The Risk attribute in an application filter allows matching applications based on their security risk level (1-5). This is the only attribute among the options that directly reflects risk. Using Risk, the administrator can create filters that include or exclude applications by risk, ensuring that only applications with acceptable risk levels are allowed.

Exam trap

The trap here is confusing application attributes like Category or Technology with Risk, which is the specific attribute for risk level.

40
MCQmedium

A network security administrator is configuring a security policy to allow access to a set of web servers. The servers are located in a dynamic environment where new instances are added frequently. The administrator wants to ensure that the policy automatically includes new web servers without manual updates. The administrator has created a dynamic address group named 'WebServers-DAG' with the filter 'WebServer'. Which additional configuration is required to ensure that the dynamic address group is populated correctly?

A.Ensure that each web server has a tag that matches the filter, such as 'WebServer', applied to its address object.
B.Create an address object for each web server and add them as static members to the dynamic address group.
C.Set the dynamic address group's filter to 'WebServer-*' to match tags that start with 'WebServer'.
D.Configure the dynamic address group to use an External Dynamic List (EDL) that contains the IP addresses of the web servers.
AnswerA

Dynamic address groups use tags to determine membership. The filter 'WebServer' will match any address object that has the tag 'WebServer'. Therefore, each web server must have an address object with that tag. When new servers are added and tagged appropriately, they are automatically included in the group without manual intervention.

Why this answer

For a dynamic address group to automatically include members, the filter must match tags applied to address objects. The filter 'WebServer' will include any address object tagged with 'WebServer'. As new web servers are deployed, tagging their address objects with 'WebServer' ensures they are dynamically added to the group, allowing the security policy to automatically cover them without manual updates.

Exam trap

The trap here is assuming that dynamic address groups can be populated by static members or EDLs, when in fact they rely exclusively on tags matching the filter expression.

41
MCQhard

A firewall administrator needs to allow traffic based on the application, not just port. Which type of object should be used in the security policy?

A.Region
B.Address
C.Service
D.Application
AnswerD

Application objects identify traffic by App-ID signatures, inspecting payload behaviour rather than relying on port numbers alone. This satisfies the stem's constraint of allowing traffic based on the application itself, since App-ID recognises the actual application regardless of the port it uses, unlike Service objects which match only port and protocol.

Why this answer

The question explicitly requires allowing traffic based on the application, not just the port. In Palo Alto Networks firewalls, Application objects are used in security policies to identify traffic by its application signature (e.g., SSL, Facebook, or custom apps), enabling Layer 7 control regardless of the port used. This is a core feature of App-ID technology, which distinguishes Palo Alto firewalls from port-based legacy firewalls.

Exam trap

The trap here is that candidates often confuse Service objects (port-based) with Application objects (app-based), assuming that specifying a port like TCP/443 is sufficient to allow HTTPS traffic, but the PCNSA exam emphasizes that App-ID is required for true application-level control.

How to eliminate wrong answers

Option A is wrong because a Region object is used to group IP addresses by geographic location (e.g., country or continent) for geo-blocking or geo-allow policies, not for identifying applications. Option B is wrong because an Address object defines a specific IP address or subnet (e.g., 10.0.0.0/8) for source or destination matching, not the application layer. Option C is wrong because a Service object defines a protocol and port number (e.g., TCP/443 for HTTPS), which matches traffic based solely on Layer 4 criteria, not the application identity.

42
MCQmedium

A network security administrator needs to create a service object that represents a custom application running on TCP port 8443 and UDP port 8443. The administrator wants to ensure that both protocols are matched by a single service object to simplify policy management. Which action should the administrator take?

A.Create a service object with protocol TCP and destination port 8443, then create another service object with protocol UDP and destination port 8443, and use both in the security policy.
B.Create an application object with protocol TCP-UDP and destination port 8443.
C.Create a service object with protocol TCP-UDP and destination port 8443.
D.Create a service group that includes two service objects: one for TCP port 8443 and one for UDP port 8443, then reference the service group in the security policy.
AnswerD

A service group can contain multiple service objects, allowing a single group to represent both TCP and UDP port 8443. This simplifies policy management because the security policy references one group instead of multiple objects, achieving the administrator's goal.

Why this answer

A service group allows multiple service objects to be grouped under one name, so referencing the group in a security policy covers both TCP and UDP port 8443. This reduces the number of objects in the policy and simplifies management. The other options either require multiple objects in the policy or use unsupported protocol combinations.

Exam trap

The trap here is assuming that a single service object can specify both TCP and UDP protocols, but PAN-OS requires separate service objects for each protocol.

43
MCQmedium

An administrator creates a dynamic address group named 'prod-servers' configured to match any tag with the value 'production'. After tagging address objects with 'Production' (capital P), the group does not include them. What is the most likely cause?

A.Tags are case-sensitive
B.The address objects are not in the same zone
C.The group needs a commit after tagging
D.Tags are not case-sensitive
AnswerA

Dynamic address group tag matching is case-sensitive, so the tag value 'production' does not match the objects tagged 'Production'. This satisfies the scenario by explaining why the group excludes those address objects despite the apparent name match.

Why this answer

Dynamic address groups in Palo Alto Networks firewalls match tags exactly, including case sensitivity. Since the group is configured to match the tag value 'production' (lowercase) and the address objects are tagged with 'Production' (capital P), the mismatch prevents the objects from being included. Tags are case-sensitive strings, so 'production' and 'Production' are considered different values.

Exam trap

The trap here is that candidates may assume tags are case-insensitive (like many other network device configurations) and overlook the exact-match requirement, leading them to choose Option D or incorrectly attribute the issue to a commit requirement.

How to eliminate wrong answers

Option B is wrong because dynamic address groups match tags globally across all zones; zone membership does not affect tag-based inclusion. Option C is wrong because tagging address objects does not require a commit to update the dynamic group membership — the group is evaluated in real time based on current tags. Option D is wrong because tags are explicitly case-sensitive in Palo Alto Networks firewalls, as demonstrated by the mismatch in this scenario.

44
MCQeasy

Refer to the exhibit. An admin reviews the traffic log and sees that traffic from 192.168.1.100 to 10.0.0.50 is allowed by rule 'rule1'. The rule uses a service group 'web-services' which includes 'service-http' and 'service-https'. However, the admin intended to block HTTPS traffic. What is the misconfiguration?

A.The application web-browsing should not be in the rule
B.The service group should not include service-https
C.The rule action should be deny
D.The source IP should be an address group
AnswerB

The service group 'web-services' bundles service-http and service-https, so the allow rule matches HTTPS traffic the administrator meant to block. Removing service-https from the group narrows the match to HTTP only, aligning the rule with the intended policy.

Why this answer

The service group 'web-services' includes both 'service-http' (TCP/80) and 'service-https' (TCP/443). Since the rule allows traffic matching any service in the group, HTTPS traffic is inadvertently permitted. To block HTTPS while allowing HTTP, the admin must remove 'service-https' from the service group or create a separate rule.

Exam trap

Palo Alto Networks often tests the distinction between service objects (port-based) and application objects (payload-based), and the trap here is that candidates may think removing the application 'web-browsing' would fix the issue, but the rule uses a service group, not an application.

How to eliminate wrong answers

Option A is wrong because the application 'web-browsing' is not part of the rule configuration described; the rule uses a service group, not an application object, so removing an application would not address the service misconfiguration. Option B is correct as explained. Option C is wrong because changing the rule action to deny would block all traffic matching the rule, including the intended HTTP traffic, which is not the desired outcome.

Option D is wrong because the source IP being an address group is irrelevant to the issue; the problem lies in the service group definition, not the source addressing.

45
MCQmedium

An administrator is creating a security policy rule that must allow traffic from a group of users who are currently logged into the firewall via GlobalProtect. The administrator wants the rule to automatically include all users who are members of the 'Marketing' group in the directory service. Which type of object should be used in the Source User field of the security policy rule?

A.Dynamic User Group
B.Address Group
C.Static User Group
D.Service Group
AnswerA

A Dynamic User Group is an object that automatically populates with users based on tags or attributes from the directory service. It can be configured to include users who are members of a specific group, such as 'Marketing'. This allows the security policy to dynamically match users as they log in or out, without manual updates. It is the correct object type for this scenario because it leverages user group information from the directory.

Why this answer

A Dynamic User Group automatically includes users based on directory attributes, such as group membership. It can be configured to match users in the 'Marketing' group and updates dynamically as users log in or out. This ensures the security policy remains current without manual intervention.

Static user groups, address groups, and service groups do not provide this automatic, directory-based user matching.

Exam trap

The trap here is confusing user groups with address or service groups, or assuming a static user group can automatically update from the directory.

46
MCQhard

A security administrator is configuring an External Dynamic List (EDL) for IP addresses that will be used in a security policy to block malicious traffic. The EDL is hosted on an internal web server at https://edl.example.com/blocklist. The administrator wants to ensure that the firewall can retrieve the list and that it is updated every hour. Which configuration is required for the EDL to function correctly?

A.Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and ensure that the firewall has a valid certificate to authenticate to the web server.
B.Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and configure a custom URL category to include the EDL.
C.Configure the EDL with source URL https://edl.example.com/blocklist, set the recurring update to hourly, and ensure that the firewall can resolve the DNS name and has a route to the web server.
D.Configure the EDL with source URL http://edl.example.com/blocklist, set the recurring update to hourly, and add the EDL to a security policy as a source address.
AnswerC

For the firewall to retrieve the EDL, it must be able to resolve the hostname to an IP address and have network connectivity to the server. The EDL configuration includes the source URL and update interval. The firewall uses its management interface or a specified interface for EDL retrieval, so DNS and routing are essential. Certificate authentication is not always required, especially if the server uses a publicly trusted certificate.

Why this answer

For an EDL to be retrieved, the firewall must be able to resolve the domain name and reach the server. The update interval is set in the EDL configuration. Certificate authentication is only needed if the server requires it and the firewall does not trust the certificate.

Thus, ensuring DNS resolution and network connectivity is fundamental.

Exam trap

The trap here is focusing on certificate authentication or URL category configuration, while overlooking the basic network requirements of DNS resolution and routing to the EDL source.

47
Drag & Dropmedium

Drag and drop the steps to configure a VLAN interface on a Palo Alto Networks firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VLAN interface setup involves creating VLAN, assigning interfaces, IP address, security policy, and commit.

Ready to test yourself?

Try a timed practice session using only Managing Objects questions.